Author Topic: Microsoft set to issue single security bulletin on Tuesday  (Read 1106 times)

Online javajolt

  • Administrator
  • Hero Member
  • *****
  • Posts: 36126
  • Gender: Male
  • I Do Windows
    • windows10newsinfo.com
Microsoft is set to publish a single security bulletin on Tuesday, consisting of two patches that will address flaws in PowerPoint. According to the advance notice, the bulletin will address vulnerabilities in PowerPoint that could result in remote execution of code, thanks, in part, to a malicious PowerPoint file.


While not expressly mentioned, the expectation is that this month’s patch from Microsoft will address the warning it issued in April.

At that time, Microsoft’s Bruce Dang and Jonathan Ness said that:

“The Malware samples we have seen exploiting this vulnerability are the first reliable exploits we have seen in the wild that infect Office 2003 SP3 with the latest security updates. Office 2003 SP3 (released Sept 2007) had a good run being safe from the bad guys but we missed this bug while back-porting fixes found in the Office 12 fuzzing effort to Office 2003 SP3.”

The advance notice lists a critical and important patch for PowerPoint. In addition to the PowerPoint patch on Tuesday, Windows 7 users will also see patches as well -- only these will be placebo test versions.

“Starting this Tuesday (May 12th) we will release up to ten test updates to PCs running the Windows 7 RC in order to verify our ability to deliver and manage updating of Windows 7 in certain real-life scenarios,” announced Microsoft's Brandon LeBlanc on the Windows

Team blog last month.

“These updates do not deliver any new features or fixes. This is the second set of test updates we’ve released to test the updating mechanism for Windows 7,” he added.

If you want more than just one patch to focus on tomorrow, Adobe is expected to keep its promise of patches for the latest round of PDF-related vulnerabilities.

According to the most recent reports from the digital document gurus, they are “in the process of fixing the issue, and expect to make available product updates for the relevant supported Adobe Reader and Acrobat versions and platforms by May 12th, 2009.”
Patches for Adobe Reader and Acrobat versions 9, 8, and 7 on Windows, versions 9 and 8 on Macintosh, as well as updates for versions 9 and 8 on UNIX, are all expected at the same time.

In April, Adobe confirmed a JavaScript error that leads to malicious code execution on a system running Adobe Acrobat or Reader. This JavaScript-related vulnerability exists on all versions of Acrobat and Acrobat Reader -- no matter the version or platform (Linux, Windows, or Mac).

“The most recent exploit discovered in Adobe Reader leaves many eagerly awaiting the delivery on Tuesday of the security patch. While there is a relatively small number of patches from Microsoft this month, IT departments will clearly have plenty to keep them busy,” Lumension’s security and forensic analyst Paul Henry said.