Critical Internet Explorer patch in MS security update
by Steven Williamson
on 15 February 2012, 13:25
Tags:
Microsoft (NASDAQ:MSFT)
Quick Link: HEXUS.net/qabcof
Add to My Vault:
Please log in to view Printer Friendly Layout |
|
Security update MS12-010, is said to resolve four privately reported vulnerabilities in Internet Explorer.
“The most severe vulnerabilities could allow remote code execution if a user views a specially crafted web page using Internet Explorer,” reads the bulletin. "An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.”
The security update applies to Internet Explorer 7, Internet Explorer 8, and Internet Explorer 9.
"The Internet Explorer bulletin should be considered a top priority, as there is a risk of code execution attacks," warned Jim Walter, manager of McAfee's threat intelligence service.
"If not attended to, browser exploits can be particularly harmful."
Vulnerabilities in Windows Kernel-Mode drivers, C Run-Time Library .NET framework, and Silverlight have also been exposed as critical.
All four critical updates refer to a code that could allow remote code execution on a client system if a user views a specially crafted web page
Overall there are nine patches correcting a total of 21 vulnerabilities in this week’s update.
For more details check out the Microsoft bulletin.