Microsoft Corporation has released security updates to its Windows operating system and Internet Explorer Web browser to address a series of flaws and vulnerabilities, three of which are considered critical. Both Microsoft and security experts recommend users download and install the patches as soon as possible to maintain the integrity of their systems and personal information.
Microsoft’s release of the updates was briefly hampered Tuesday by corrupted files in the company’s online Download Center; the errors affected only the Internet Explorer update ad did not interfere in any way with Microsoft Update or users updating via Windows Update.
Fixes to Internet Explorer include:
- a vulnerability in the way IE rendered JPEG images which could permit memory corruption and execution of arbitrary code;
- a cross-domain vulnerability which could enable remote attackers to access data or execute programs on a system by getting a user to browse from a Web site to a Web folder using WebDAV;
- a vulnerability in the way IE instantiates COM objects such as shell32.dll and dmdskmgr.dll which are not intended to be used by Internet Explorer;
Other "critical" fixes in the security update include a patch for a flaw in Windows’ Plug and Play (PnP) technology and a "wormable" defect in Windows Print Spooler Service which could enable attackers to install programs, access arbitrary data on the machine, or create new users with full access to the system.
The updates also include a denial-of-service attack against Remote Desktop Services (RDP), an issue with Telephony Application Programming Interface (TAPI) affecting systems all the way back to Windows 98 which could enable remote attackers to execute code on affected systems, and a patch to Microsoft’s Kerberos implementation which could have exposed systems to denial-of-service attacks, service crashes, and spoofing attacks.
Editors' Recommendations
- Get this Asus laptop with a year of Microsoft Office for $199
- How to build a table of contents in Microsoft Word
- How to delete or hide chats in Microsoft Teams
- Save $150 on a lifetime license for Microsoft Office for PC
- Even the new mid-tier Snapdragon X Plus beats Apple’s M3