Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
    Digg this story   Add to del.icio.us  
Microsoft's big patch day fixes 26 flaws
Published: 2006-10-10

Microsoft released ten patches on Tuesday to plug 26 security holes in its Windows operating system and Office productivity suite, giving 15 of the vulnerabilities its most severe threat rating of "critical."

The massive update fixed 15 flaws in various components of the software giant's Office applications for Windows and 12 flaws in the Mac version of the productivity suite. (Eleven of the flaws were common between the two platforms.) The company's collection of office applications has been under siege in 2006, with at least 43 flaws fixed so far this year, more than ten times the number found in 2005.

The patches fix a zero-day vulnerability that attackers have used to compromise PCs in targeted attacks. Microsoft also patched 10 Windows flaws, including another critical vulnerability in the Windows Shell that attackers had been exploiting.

Zero-day attacks, especially against Microsoft's Office products, have increased in frequency this year. The increasing trend of zero-day attacks has come at a time when researchers are increasingly taking Microsoft to task for its policies on the airing of flaw details.

Microsoft had announced last Thursday that it would release 11 patches, but the company found a problem with one of the fixes and put off the update until next month, a spokesperson said.



Posted by: Robert Lemos
    Digg this story   Add to del.icio.us  
 
Comments Mode:
One flaw per day 2006-10-11
assurbanipal (2 replies)
Re: One flaw per day 2006-10-12
Anonymous
Re: One flaw per day 2006-10-13
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus