Microsoft's Patch Tuesday filled with zero-day exploits

14.04.2009

His forecast is for the attacks to get worse and faster. He says hackers are creating code designed to avoid detection, as evidenced with  

"We see Conficker as the new standard," Kandek says. "As hacking becomes more professional these intrusions or exploits will become more silent, they will not call too much attention to themselves so they can steal identities, send out some spam or launch a [denail of service] attack." In Conficker's case, it also tricks the user into thinking their system is patched.

MS09-009 addresses vulnerabilities in Excel that were identified two months ago by Microsoft. MS09-010 addresses vulnerabilities in WordPad and Office Text Converters, and MS09-012 addresses issues in Windows.

The MS09-013 critical patch fixes problems with the Windows HTTP Service and MS09-014 is a cumulative security update for Internet Explorer.

The other patches released Tuesday were MS09-011, which was rated critical and fixes an issue with DirectX. MS09-016 is rated important and addresses DoS issues in Microsoft ISA Server and Forefront Threat Management Gateway, Medium Business Edition.