Microsoft is getting ready to break its record again. The software giant will deliver a record 17 security updates for December’s Patch Tuesday. The updates aim to fix 40 vulnerabilities in Windows, Internet Explorer, Office, SharePoint and Exchange.
Of the 17 updates, two bulletins are rated critical, 14 are rated important, and one is rated moderate. That brings the total bulletin count to 106 for the year, breaking an annual record. The number of vulnerabilities patched climbs to 266, also a new record.
“We’re addressing two issues this month that have attracted interest recently. First, we will be closing the last Stuxnet-related issues this month,” said Mike Reavy, director of the Microsoft Security Response Center. “This is a local Elevation of Privilege vulnerability, and we’ve seen no evidence of its use in active exploits aside from the Stuxnet malware.”
Active IE Exploits
He said Microsoft is also addressing the IE vulnerability described in Security Advisory 2458511. That vulnerability exists thanks to an invalid flag reference within IE. In a specially crafted attack, IE can allow remote code execution. Microsoft acknowledged target attacks attempting to exploit the vulnerability.
“Over the past month, Microsoft and our MAPP partners actively monitored the threat landscape surrounding this vulnerability, and the total number of exploit attempts we monitored remained pretty low,” Reavy said, adding that customers running IE8 are protected by default.
The WikiLeaks Effect
It’s enough that IT administrators are addressing the current denial-of-service attacks surrounding WikiLeaks, where anyone could very quickly become a target, but now organizations also have to address this disruptive Patch Tuesday with 17 bulletins, which may all require a restart, said Paul Henry, security and forensic analyst for Lumension.
“With the advancement of communication technologies such as the real-time ability to communicate using Twitter, we have ushered in a new realm of ‘hactivism,’,” Henry said. “The…