Microsoft to patch Windows 8, but stays mum on IE zero-day fix

Status
Not open for further replies.

Fiery

Level 1
Thread author
Jan 11, 2011
2,007
Microsoft Thursday said it will release seven security updates next week—including one rated critical for Windows 8 and Windows RT—to patch 12 vulnerabilities in Windows, Office, SharePoint Server and the company’s website design software.

At the same time, Microsoft warned customers that hackers are using digital certificates obtained from a Turkish certificate authority (CA). In response, Microsoft has removed the purloined certificates from Windows’ list of trusted certificates, and urged users to verify that they have applied a June 2012 update that automates the de-certification process.

Missing from Thursday’s advance notification was any news about the Internet Explorer (IE) zero-day vulnerability that hackers have been exploiting since at least Dec. 7.

Microsoft declined to comment on Thursday when asked about the timetable for the IE fix.

In an emailed statement, Dustin Childs, a group manager in Microsoft’s security group, again said that the firm has found few attacks exploiting the IE bug. “We’ve seen only a limited number of affected customers,” Childs claimed.

Read more: http://www.pcworld.com/article/2023674/microsoft-to-patch-windows-8-but-stays-mum-on-ie-zeroday-fix.html
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top