Windows gets big security update


Recommended Posts

One of the biggest security updates for more than a year is being released by Microsoft to fix 12 software flaws.

Nine of the updates apply to the Windows operating system and one is deemed critical, a rating reserved for the most serious security problems.

At least one of the loopholes being patched is already being actively exploited by malicious hackers.

Windows users are being urged to download the patches as soon as they become available on Tuesday 13 June.

Support shift

Microsoft issues its security patches on the second Tuesday of every month and June's update will be the biggest for more than a year.

This is because Microsoft is not only tackling security problems but also the fallout of a legal case that the software giant lost.

Microsoft gives advance notice of what is in its security patches to help companies plan how best to install the software and limit the impact on day-to-day business.

While most of the updates apply to Windows, two are for the Office suite of products and one for the Exchange e-mail server software.

One of the security problems being tackled in Office was found in Microsoft's Word software and the virus created to exploit it has been dubbed Backdoor.Ginwui. The virus and loophole were first discovered in mid-May.

The virus travels in an e-mail bearing a Word document that purports to summarise the results of a US-Asia summit.

Legal woes

Another of the updates has come about as a result of a courtroom clash between Microsoft and Eolas over technology in the Internet Explorer browser. The lawsuit ended with a $521m (?283m) judgement against Microsoft.

Microsoft had to re-engineer Internet Explorer to stop a technology known as ActiveX automatically starting when users visit some websites.

Before now, users could choose to apply this change to their browser, but this update makes it mandatory.

At the same time as information about the update was being released, Microsoft mentioned that it will not be able to patch Windows 98 and ME against a loophole discovered in April 2006.

Fixing this bug in the ageing software would require a major re-write of the Windows Explorer program used in these old copies of the operating system.

Microsoft is not prepared to undertake this work, given that all support for Windows 98 and ME ends on 11 July 2006.

On its security blog Microsoft wrote: "We strongly recommend that those of you who are still running these older versions of Windows upgrade to a newer, more secure version, such as Windows XP SP2, as soon as possible."

Source:

http://news.bbc.co.uk/1/hi/technology/5071656.stm

Link to comment
https://www.neowin.net/forum/topic/469655-windows-gets-big-security-update/
Share on other sites

Thanks for the info.

Btw: it would be intresting to know how Vista (B2) handles these flaws - as it got public before these fixes. I really like to hear a statement, like "Vista doesn't need these fixes, because of the rewritten network parts: it defends you from these flaws out of the box". :p But i have a feeling it won't happen... :rolleyes:

High-priority updates

Microsoft Windows XP

Windows Malicious Software Removal Tool - June 2006 (KB890830)

Security Update for Windows XP (KB914389)

Security Update for Windows XP (KB918439)

Security Update for Windows XP (KB911280)

Security Update for Windows XP (KB917953)

Microsoft Office 2002/XP

Security Update for Word 2002 (KB917335)

Security Update for PowerPoint 2002 (KB916519)

Download size: 7.3 MB , less than 1 minute

Microsoft has released a security update for Microsoft PowerPoint 2002. This update resolves a security issue that could allow arbitrary code to run when you open a malicious presentation. Details...

(dunno why thats showing up,I'm not even using Powerpoint 2002,I'll save myself 7.3MB by not installing it,thus making my total download 8.5MB instead of 15.8MB)

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • This saddens me greatly
    • Well again I do not mind seeing it charge my stuff if it does it well. "yeah charge my phone like that, charge it good"
    • Getting so tired of this push for that new useless slop over the less-useless old slop that at this point I just want M$ to have this nice, big, hearty cup of *FU*.
    • Brave Browser 1.91.168 by Razvan Serea Brave Browser is a lightning-fast, secure web browser that stands out from the competition with its focus on privacy, security, and speed. With features like HTTPS Everywhere and built-in tracker blocking, Brave keeps your online activities safe from prying eyes. Brave is one of the safest browsers on the market today. It blocks third-party data storage. It protects from browser fingerprinting. And it does all this by default. Speed - Brave is built on Chromium, the same technology that powers Google Chrome, and is optimized for speed, providing a fast and responsive browsing experience. Brave Browser also features Brave Rewards, a system that rewards users with Basic Attention Tokens (BAT) for viewing opt-in ads. This innovative system provides an alternative revenue model for content creators and a way to support the Brave community. SlimBrave Neo takes all the good things about Brave and makes them even better by keeping everything clean, light, and privacy-focused. It removes the extra clutter, turns off features you might not need, and cuts down on anything that could slow you down or collect unnecessary data. Because it relies on simple settings and policies instead of modifying the browser itself, you still get full Brave compatibility—just in a smoother, lighter, and more privacy-friendly package. Brave Browser 1.91.168 changelog: Web3 Added “Get Started” section to the “Portfolio” page. (#54029) Added the ability to view “Asset Distribution” in “Portfolio”. (#54028) Added dotted texture to wallet line chart. (#54216) Migrated Jupiter swap provider to “Gate3”. (#51848) Updated the “Permission” panel to display the site origin. (#54482) Updated NFT balance fetch to remove duplicate entries prior to fetching balances. (#55036) Fixed missing back button on the “Deposit Funds” page. (#55842) Fixed reloading an account tab redirecting to the “Accounts” page. (#54826) Leo Added support for text file uploads with renderer-based extraction. (#54062) Added PDF text extraction at upload time. (#51911) Updated display of Brave Leo attachment previews to scroll horizontally instead of vertically. (#54258) Updated the “Copy” button for the code block header to be sticky when scrolling. (#53704) Updated the staged content in the Leo side panel to be the active tab. (#53533) Updated the search terms in the answer’s footer to be left aligned. (#54204) Fixed crash which could occur in certain cases when using multiple tool requests. (#55438) General Added support for Brave Origin. (#37127) [Security] Added the ability to disable or delay automatic extension updates when brave://flags/#brave-user-extension-auto-update is enabled. (#7200) Enabled ability to force context menu using “Shift + Right Click” by default. (#54790) Improved performance by caching adblock DATs. (#27161) Updated background color for PWA install button in the omnibox. (#54736) Fixed tab hover card position when using vertical tabs. (#54199) Fixed extra border displaying around the content area when vertical tabs are used on macOS. (#54153 & #52961) Fixed audio farbling distortion in multi-voice Web Audio API synthesized music. (#52906) Upgraded Chromium to 149.0.7827.54. (#55943) Download: Brave Browser 64-bit | 1.2 MB (Freeware) Download: Brave Browser 32-bit View: Brave Homepage | Offline Installers | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Thanks Microsoft but no, I find both iterations of Outlook terrible nowadays and switched back to Thunderbird at home.
  • Recent Achievements

    • Dedicated
      JKR earned a badge
      Dedicated
    • One Year In
      CHUNWEI earned a badge
      One Year In
    • Conversation Starter
      FBSPL earned a badge
      Conversation Starter
    • Week One Done
      I2D earned a badge
      Week One Done
    • Week One Done
      Dr Jared Dental Studio earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      471
    2. 2
      PsYcHoKiLLa
      255
    3. 3
      Skyfrog
      80
    4. 4
      FloatingFatMan
      62
    5. 5
      Michael Scrip
      62
  • Tell a friend

    Love Neowin? Tell a friend!