Microsoft's May Patch Tuesday - What You Need to Know

By Alexandra Burlacu | May 10, 2012 09:00 AM EDT

Share This Story

  • Print
  • Email

As part of May's Patch released on Tuesday, May 8, Microsoft fixes 23 security flaws in all versions of Windows, Microsoft Office, Silverlight, and .NET Framework.

According to Microsoft's Security Bulletin Summary released on Tuesday, three of the seven bulletins were rated as "critical," while the other four were rated as "important."

Follow us

Except for two bulletins, all others addressed remote code execution vulnerabilities. The bugs fixed in May's security patch are not actively targeted, at least not for now. Microsoft, however, said that exploit for them was likely.

Highest Priority Security Updates

The RTF Mismatch Vulnerability (MS12-029) should be seen as the highest priority for most organizations. The update patches a flaw in Rich Text Format files. The vulnerability can be exploited through Microsoft Office 2003 and 2007 to control an end user's machine. Simply viewing an attached file in Microsoft Outlook's preview pane can trigger the exploit, which will then take control of the end user's machine without requiring any user interaction.

Microsoft Office for Mac 2011 is also included in the list of affected programs. Mac users need to be aware of increasing security risks and pay attention to updates to protect their software, especially with all the recent hype involving infecting Macs. A recent attack exploited an old vulnerability in Microsoft Word for Mac.

Microsoft also focused on the True Type Fonts vulnerability, which was exploited late last year by the Duqu Malware. Microsoft fixed the vulnerability in December's Patch Tuesday update (MS11-087). The internal security team also identified other products, including .NET, Windows, Silverlight, and Office, which contained the vulnerable code, and fixed them in the MS12-034 update. Those applications had several other bug fixes pending, and MS12-034 is a set of patches with such bug fixes, therefore it is very important to be installed.

Excel, Visio Patches in Microsoft Office

Microsoft patched six bugs in Excel (MS12-030), including file format memory corruption, remote code execution vulnerabilities, and record heap overflow. It also fixed one bug in Visio (MS12-031). Both these Microsoft Office bulletins addressed file-format vulnerabilities, which could be exploited with a certain file. A successful infection could allow a cyber attacker to gain control over an end user's targeted machine.

XBAP Patch

Lastly, the XBAP patch is rated as "critical," but it seems this bulletin is the least urgent one to install. XBAP is a Microsoft browser-based application delivery format. In order to be exploited without any user interaction, the attacker should already be in the same Intranet zone as the target. According to security experts, administrators should completely disable XBAP if there is no specific business need. This way, it would be less likely for the issue to be targeted.

(reported by Alexandra Burlacu, edited by Dave Clark)

 

Get the Most Popular Mobile&Apps Stories in a Weekly Newsletter

© 2013 Mobile & Apps All rights reserved. Do not reproduce without permission.

Join Our Conversation

Smartphones
Google Nexus 4 White VersionWhite Nexus 4 To Launch On June 10 Rocking Latest Android 4.3
Galaxy S4 Best Selling Samsung Smartphone Of All Time?
Android 4.2.2 Jelly Bean Coming Soon For HTC One; Google Edition of HTC One On The Way
Android 4.1.2 Jelly Bean Official Firmware Update For Samsung Galaxy S3 I9300 Via XXEMD2 [How To Install]
Tablet / Laptop / PC
MacBook AirNew MacBook Air To Debut In June With Intel's New Haswell Processor?
Nexus 7 Refresh Teased In Google+ Hangouts Video, Sports Glowing Notification Light
AMD Unleashes Radeon 8900M Mobile GPU: Get It In MSI GX70 Gaming Laptop
Dell XPS 10 Drops Price To $300, Marking A New Low For Windows RT
Gadgets
Xbox Release Event InviteNext Microsoft Xbox To Sport Dashboard UI Update And Tile Changes
Google Media Streamer Hits FCC To Replace Nexus Q
Google Glass Raises Lawmakers' Concerns: Congress Demands Answers About Privacy
Seven New Apps Coming To Google Glass: Facebook, Twitter, And Evernote Included
OS / Software
HTC OneAndroid 4.2.2 Jelly Bean Coming Soon For HTC One; Google Edition of HTC One On The Way
Android 4.1.2 Jelly Bean Official Firmware Update For Samsung Galaxy S3 I9300 Via XXEMD2 [How To Install]
Windows Phone Took Third Spot From BlackBerry In Latest Worldwide Market Share Report
Sprint Releases Software Update For HTC One: Key Sensitivity Issues To Be Fixed
Internet / Social Media
The Yahoo logYahoo Is Eyeing Tumblr
Google I/O 2013: Chrome Web Browser Now Has 750 Million Active Users
Google I/O 2013: Google Maps Gets New UI And Google+ Hangouts Shows Massive Improvements
Gtalk Chat Integration Coming To Outlook.com
What's App
Intellicam Windows Phone 8Intellicam App Brings First Hands-Free Camera Feature To Windows Phone 8
Seven New Apps Coming To Google Glass: Facebook, Twitter, And Evernote Included
Itsdagram Available Now For Windows Phone: Best Instagram Client Around
Google I/O 2013: Chrome Web Browser Now Has 750 Million Active Users

DON'T MISS

Galaxy S3 Sapphire Black
Android 4.1.2 Jelly Bean Official Firmware Update For Samsung Galaxy S3 I9300 Via XXEMD2 [How To Install]
The update comes with some features like Group CastApp and Page Buddy.
MacBook Air
New MacBook Air To Debut In June With Intel's New Haswell Processor?
Apple is expected to update its hardware lineup as soon as June with a new MacBook Air likely
HTC One
Android 4.2.2 Jelly Bean Coming Soon For HTC One; Google Edition of HTC One On The Way
According to Android Authority, "@LlabTooFeR says he knows about the HTC One without Sense 'for a
Galaxy S4 Launch in Korea
Galaxy S4 Best Selling Samsung Smartphone Of All Time?
Galaxy is the new iPhone, as the Samsung Galaxy S4 approaches 10 million devices shipped in less
Google Nexus 4 White Version
White Nexus 4 To Launch On June 10 Rocking Latest Android 4.3
The white Nexus 4 that created a lot of buzz among rumor mills recently, finally has a launch date:
Jabra HALO2 Bluetooth Stereo Headset
Amazon Deals Of The Day: Sony Xperia Z, Jabra HALO2 Bluetooth Stereo Headset And More
Here are some deals for those on a right budget, or for those who can't pass up on a good deal.

Nokia Lumia 925
Windows Phone Took Third Spot From BlackBerry In Latest Worldwide Market Share Report
The Windows Phone platform is definitely growing, but can it continue with this momentum?
HTC One
Sprint Releases Software Update For HTC One: Key Sensitivity Issues To Be Fixed
According to a post on Sprint's community page, the software build number 1.29. 651.10 has been
Pentagon
Apple iOS 6 Devices Cleared For Military Use In U.S.
The Pentagon has approved Apple devices running iOS 6 for use on its networks, which means Apple
RIM BlackBerry 10
BlackBerry Live: 120,000 Apps in BlackBerry World, Gaining on Windows Phone
The numbers are in, and it appears BlackBerry World might walk over Windows Phone sooner or later.
Copyright © 2013 Mobile & Apps All rights reserved. mobilenapps
Real Time Analytics