Bugs and Fixes: News from Avast, Apple and Microsoft

19.04.2011

This month Microsoft released a massive patch on Tuesday (April 12) containing seventeen security bulletins which addressed a whopping 64 vulnerabilities. Updates address vulnerabilities in everything from Internet Explorer, Windows, Office, and the .NET Framework, as well as a number of other systems. Nine of these updates are rated 'critical' while the rest are rated 'important.'

Update MS11-018, which is rated 'critical' for IE 6 through 8 on Windows, resolves five vulnerabilities. If you were to view a specially-crafted web page using IE then an attacker could employ remote code execution by exploiting the unpatched vulnerability on your system, allowing the attacker to gain the same rights as the local user. the update addresses the vulnerabilities by "modifying the way that Internet Explorer handles objects in memory, content during certain processes, and script during certain processes."

Another update, MS11-033 (bearing an 'important' rating) addresses a vulnerability found in WordPad Text Converters which affects Microsoft Windows. This vulnerability could permit remote code execution if you were to open a specially-crafted file using WordPad, allowing the attacker to gain the same rights as the local user. Update MS11-033 fixes this bug by altering the way that the WordPad Text Converters handle these custom attack delivery files.

As always, to prevent your system from being exploited you should install these updates as soon as possible using Windows Update. To learn more about each update--and to download them manually--visit the Microsoft Safety & Security Center . Also check out PCWorld's Security Alert article on the topic by Tony Bradley .