Microsoft has taken the unusual step of releasing two security patches before their usual monthly release. Microsoft typically only releases these "out-of-cycle" patches when hackers are exploiting the flaw in real-world attacks and as a result we consider these to be important patches to apply.
Both patches are classed as Critical.
The first patch fixes a reported vulnerability in various MS Windows applications such as Word & PowerPoint. The second patch fixes a reported vulnerability in all versions of Internet Explorer.
Our advice is…
- Ensure that the critical patches are deployed to all affected Windows desktop and server operating systems immediately.
- Ensure that all Anti-virus and Malware blocking software packages are fully up to date, and properly configured firewalls are in place within your environment.
In summary…
- Update your Desktop and Server computers immediately with the critical patches (MS10-001, MS10-002).
- Please also make sure that all additional IT Security solutions (Anti Virus, Anti Malware and Firewall) are in place, are up to date and are appropriate for your environment.
Table 1: Details of MS Patches released Thursday 21/01/2010
| MS Link |
ITSL Summary |
Severity |
Affected Software |
Restart after patch |
| MS10-001 |
This security update resolves a reported vulnerability in MS Windows which could allow remote code execution in circumstances where a user viewed content rendered in a specific font type (EOT). Our advice is to immediately patch all affected devices listed.
|
Critical |
Windows 2000, XP, Server 2003, Vista, Server 2008, Windows 7 & Server 2008 Revision 2 |
May Require Restart |
| MS10-002 |
This patch is an emergency ‘out of band’ release to deal with the security vulnerability in all supported versions of Internet Explorer.
|
Critical |
Internet Explorer 5, 6, 7 & 8
|
Yes |
| Rating |
Definition |
| Critical |
A vulnerability whose exploitation could allow the propagation of an Internet worm without user action. |
| Important |
A vulnerability whose exploitation could result in compromise of the confidentiality, integrity, or availability of users data, or of the integrity or availability of processing resources. |
| Moderate |
Exploitability is mitigated to a significant degree by factors such as default configuration, auditing, or difficulty of exploitation. |
| Low |
A vulnerability whose exploitation is extremely difficult, or whose impact is minimal. |