Microsoft on Tuesday released 12 security bulletins. February’s bulletins include three rated critical and nine rated important to address 22 unique vulnerabilities in Microsoft Office, Windows, Internet Explorer, and Internet Information Services (IIS).
“Among the six previously public vulnerabilities fixed, the Internet Explorer Cascading Style Sheet issue is the only one Symantec is seeing actively being used in attacks,” said Joshua Talbot, security intelligence manager for Symantec Security Response. “The attacks aren’t extremely widespread, but we did recently see a spike in activity. IT managers should patch this right away, especially those that have not implemented the temporary work-around released last month.”
Talbot said at least one of the other critical Internet Explorer vulnerabilities patched is also likely to be exploited. The uninitialized memory corruption vulnerability appears to be even easier to take advantage of than the Cascading Style Sheet flaw, he said, so, if cybercriminals are able to reverse-engineer the patch — and they will certainly try — we’ll probably see exploits.
“It’s great to see so many vulnerabilities getting fixed, but months like this can be challenging for IT managers,” Talbot said. “Considering Adobe is also releasing a security update today and a major Java release is expected from Oracle in the coming weeks, February is going to be busy. The key will be prioritizing. Patch all the ‘critical’ vulnerabilities first, and then move on from there.”
IE Patch Making Noise
Paul Henry, forensic and security analyst at Lumension, called February’s Patch Tuesday “very disruptive” with several updates impacting nearly the full operating-system product line from Microsoft and requiring a reboot.
“While a pair of Zero Day security issues have now been patched, we still have not received a patch for the MHTML issues that impact all versions of Internet Explorer, meaning we can look forward to an equally disruptive Patch Tuesday…