Microsoft issued 11 security bulletins on Patch Tuesday covering a total of 17 vulnerabilities, 10 of them critical. The 11 patches address the Windows operating system, the Internet Explorer Web browser, Microsoft Office and other programs.
“While the batch of critical vulnerabilities all require some sort of user interaction to exploit, the interaction can be as simple as visiting a trusted Web site that has first been exploited by an attacker,” said Ben Greenbaum, senior research manager for Symantec Security Response.
As consumers and enterprises become more savvy to security risks, he added, attackers are finding ways to distribute malware through trusted sites in addition to distributing via an attachment or random link in an e-mail.
“These vulnerabilities underscore the importance of having a full security suite to protect consumers and enterprises from being exploited since they can no longer only rely on traditional best practices alone, such as avoiding unknown or unexpected e-mail attachments or following Web links from unknown sources,” Greenbaum said.
Happy Valentine’s Day
“This month’s patches are going to require a great deal of man-hours for IT admins, from determining what is affected to the testing and deployment processes. IT administrators might be spending this Valentine’s Day in the office,” said Paul Zimski, senior director of market strategy at Lumension Security.
“Because we are so used to trusting and opening Office attachments, the fact that there are three critical patches for Office opens up a huge window for a potential attack, whether general or targeted,” Zimski said.
Indeed, five of the 11 advisories this month are client-side issues that are part of the daily experience for users. These are likely responses from Microsoft to specific, targeted attacks that have been building up over the past few months.
“This is bad news for enterprises,” said Tyler Reguly, security researcher for…