After a record-matching February that flooded corporate security departments with 13 bulletins to address 26 flaws, Microsoft’s March Patch Tuesday cycle will be more manageable for IT administrators. On March 9, Microsoft will ship two security updates to fix eight vulnerabilities in Windows and Office.
In its monthly advance notification, Microsoft gave a sneak peak into the bulletins. Both are marked important, Microsoft’s second-highest severity rating.
But despite not earning critical status, the flaws are hardly benign. The eight vulnerabilities Microsoft outlined could open the door to attackers to insert malicious code onto unpatched computers.
Pesky Office Bugs
The first bulletin will fix vulnerabilities in Windows XP, Vista and Windows 7. This bulletin also affects the most recent service packs for XP and Vista, SP2 and SP3. Microsoft said both the 32-bit and 64-bit editions of these operating systems have the important bugs. The second bulletin will tackle bugs in Excel 2002, Excel 2003, and Excel 2007 on Windows, as well as Excel 2004 and Excel 2008 for the Mac and some Excel issues in Office service packs.
From what Paul Henry, a security and forensic analyst at Lumension, has seen, it doesn’t appear that the bulletins released will address all the issues in the wild.
“Interestingly, Microsoft also announced some end-of-life dates of Windows XP, so customers will soon have to start updating these operating systems, which include Windows XP Service Pack 2, as they will no longer be supported after July 13, 2010,” Henry said. “Customers are being encouraged to upgrade to Service Pack 3 or to Windows 7 as soon as possible.”
The VBScript Vulnerability
On Monday, customers were alerted to a VBScript vulnerability that was exposed on supported versions of Microsoft Windows 2000, Windows XP, and Windows Server 2003 through the use of Internet Explorer. But Microsoft’s March patches will not address…