Microsoft fixes 46 flaws in Windows, IE, Office, other products

Companies should prioritize three security bulletins that are rated critical

Fourteen critical vulnerabilities in Internet Explorer were among the targets of Microsoft's monthly batch of security patches released Tuesday. In all, it fixed 46 vulnerabilities across products including Windows, Internet Explorer and Office.

The patches were organized in 13 security bulletins, three flagged as critical and ten as important. The critical bulletins, MS15-043, MS15-044 and MS15-045, cover remote code execution vulnerabilities in Windows, IE, Office, Microsoft .NET Framework, Microsoft Lync and Silverlight.

The priority for administrators should be MS15-043 which fixes 22 vulnerabilities in Internet Explorer, of which 14 are rated critical, said Wolfgang Kandek, the CTO of security firm Qualys, via email. Critical vulnerabilities in IE allow attackers to execute arbitrary code on machines when their users visit malicious Web pages, and attackers have a variety of techniques in their arsenal to achieve this, he said.

However, not all remote code execution vulnerabilities end up being exploited by criminals. Last year, only five percent of such vulnerabilities were targeted in real attacks.

"The difficulty is predicting which 5 percent," Kandek said. "I think it makes sense to look at the past to see what got attacked and what vulnerabilities are covered in exploit packs and prepare accordingly."

Next on the list of priorities should be MS15-044 because it fixes two vulnerabilities in a font parsing library used by many Microsoft products. Attackers could exploit these flaws by embedding a specially crafted font in documents or Web pages.

"Patch quickly, in less than two weeks if you can," Kandek said.

One reason for that is that criminals are quicker than ever to adopt exploits for popular programs, especially reliable ones they can use at scale. But companies should also start to get used to an accelerated patch tempo because Microsoft plans to push out updates for Windows 10 as they're ready instead of on a fixed schedule.

Companies will get the option to delay those updates for some systems by using a new service called Windows Update for Business. However, once a security patch reaches consumer deployments, the vulnerabilities it fixes are essentially revealed.

It's been known for a long time that attackers can reverse engineer patches to figure out where the bugs are and how to exploit them, so companies might not have the luxury of delaying patches for too long.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags patchesMicrosoftsecuritypatch managementExploits / vulnerabilitiesqualys

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Lucian Constantin

IDG News Service
Show Comments

Father’s Day Gift Guide

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

David Coyle

Brother PocketJet PJ-773 A4 Portable Thermal Printer

I rate the printer as a 5 out of 5 stars as it has been able to fit seamlessly into my busy and mobile lifestyle.

Kurt Hegetschweiler

Brother PocketJet PJ-773 A4 Portable Thermal Printer

It’s perfect for mobile workers. Just take it out — it’s small enough to sit anywhere — turn it on, load a sheet of paper, and start printing.

Matthew Stivala

HP OfficeJet 250 Mobile Printer

The HP OfficeJet 250 Mobile Printer is a great device that fits perfectly into my fast paced and mobile lifestyle. My first impression of the printer itself was how incredibly compact and sleek the device was.

Armand Abogado

HP OfficeJet 250 Mobile Printer

Wireless printing from my iPhone was also a handy feature, the whole experience was quick and seamless with no setup requirements - accessed through the default iOS printing menu options.

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?