As part of today’s Patch Day, Microsoft released a security bulletin describing two new security vulnerabilities affecting Internet Explorer (IE). Similar to the flaws in last month’s update, both of these vulnerabilities are what developers call “use after free” vulnerabilities – a type of memory corruption flaw that attackers can leverage to execute arbitrary code.
“Use After Free” Flaws: A New Theme for IE Vulnerability
IE Update Fixes Multiple Use-After-Free Vulnerabilities
As part of today’s Patch Day, Microsoft released a security bulletin describing nine new security vulnerabilities affecting Internet Explorer (IE). Similar to the last few IE updates, all nine of these security flaws are what developers call “use after free” vulnerabilities,
Two IE Bulletins Double the Browser Updates
In a relatively unusual move, Microsoft released two Internet Explorer (IE) security bulletins today, rather than their typical single cumulative update. Combined, the two bulletins fix 14 vulnerabilities in the popular web browser, many of which allow attackers to execute code on vulnerable Windows systems.
Emergency Flash Update Fixes “In the Wild” Vulnerabilities
Adobe Flash Player displays interactive, animated web content called Flash. Although Flash is optional, 99% of PC users download and install it to view multimedia web content. It runs on many operating systems, including mobile operating systems like Android.
Avoid Drive-by Downloads; Patch IE
As part of today’s Patch Day, Microsoft released a security bulletin describing three new security vulnerabilities affecting Internet Explorer (IE). Technically, the new vulnerabilities seem only to affect IE 9 and 10, yet Microsoft has released the cumulative update for all versions. They rate this update as Critical.
Three Critical Vulnerabilities Only Affect IE 9
As part of today’s Patch Day, Microsoft released a security bulletin describing three new security vulnerabilities that affect Internet Explorer (IE) 9.0, running on Windows Vista, 7, and Server 2008.
Adobe Flash Player Update and Reader X 0day
Adobe Flash Player displays interactive, animated web content called Flash. Although Flash is optional, 99% of PC users download and install it to view multimedia web content. It runs on many operating systems, including mobile operating systems like Android.
Four Updates Repair Office and Server Software Vulnerabilities
Today, Microsoft released four security bulletins that fix around 20 vulnerabilities in a wide range of Microsoft Office and Server Software products. The affected products include.
Early Adobe Flash Patch Corrects 25 Vulnerabilities
Adobe Flash Player displays interactive, animated web content called Flash. Although Flash is optional, 99% of PC users download and install it to view multimedia web content. It runs on many operating systems, including mobile operating systems like Android.
Final IE 0day Update: Microsoft Out-of-Cycle Patch Available
If you’ve read my two posts [ 1 / 2 ], and watched this week’s video, you already know all about the zero day vulnerability plaguing Internet Explorer (IE) this week. In my last update, I mentioned Microsoft promised to release a full, out-of-cycle patch for this serious vulnerability today. True to their word, they did just that.
- 1
- 2