SHARE
Facebook X Pinterest WhatsApp

Microsoft Readies Five ‘Critical’ Fixes for Tuesday

Aug 7, 2009

Microsoft plans to release nine bug patches next week for its monthly Patch Tuesday drop — five of them rated as “critical”.

This month’s collection of security bug fixes will be about average for Microsoft’s (NASDAQ: MSFT) regular monthly patch release. However, the company did ship two so-called “out-of-band” bug patches on July 28 to block exploits that were scheduled to be exposed the following day at the Black Hat security conference in Las Vegas.

Still, even with those two fixes, next week’s patches aren’t likely to match Microsoft’s biggest bundle of fixes, which came with June’s Patch Tuesday event.

Although Microsoft does not detail bugs in advance of patch availability, it said today that August’s collection of fixes primarily affects versions of Windows, including Windows 2000 Service Pack 4 (SP4), XP SP2 and SP3, and Vista, as well as Windows Server 2003 and 2008. Windows 7 is not on the list, however.

Additionally, some of the vulnerabilities affect Outlook Express versions 5.5 and 6, along with Windows Media Player 9, 10, and 11.

Meanwhile, one patch fixes critical holes in Microsoft Office for XP and Office 2003. The same patch also fixes holes in Visual Studio, in Internet Security and Acceleration Server, and in BizTalk Server.

One bonus is that this round of patches addresses a zero-day vulnerability that was discovered in mid-July — too late for the July Patch Tuesday drop.

That bug, for which Microsoft has already released a workaround, is in the Office Web Components, used in publishing documents on a Web site.

Still, some security experts say, Microsoft has its work cut out for it.

“Despite Microsoft’s best efforts to stay ahead of the attackers, zero-day vulnerabilities like the Office Web Components flaw are being actively discovered and targeted by attackers,” Sheldon Malm, senior director of security strategy for security vendor Rapid7, said in an e-mail to InternetNews.com. “Rapid7 would not be surprised if yet another zero-day flaw surfaces in the following weeks, as has been the case in recent months.”

Recommended for you...

Best Internet Security Software
Devin Partida
Mar 23, 2022
HP Wolf Security Report Shows Threat Landscape Getting Scarier
Rob Enderle
Oct 15, 2021
Microsoft Gets Rid Of Passwords: I Can Almost Hear Angels Singing
Rob Enderle
Sep 17, 2021
The Coming AI Threats We Aren’t Prepared For
Rob Enderle
Aug 27, 2021
Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.