Microsoft have released just one security bulletin for this month's Patch Tuesday.
It is considered critical for Windows 2000 environments and low priority on systems running Microsoft Windows XP, Vista, Windows 7, Windows 2003 & Windows 2008.
The patch fixes a vulnerability with the font engine. If exploited, it could allow an attacker to control and run code remotely.
Our usual advice is…
- Ensure that the critical patches are deployed to all Windows desktop and server operating systems and Software, where appropriate, immediately.
- Ensure that all Anti-virus and Malware blocking software packages are fully up to date, and properly configured firewalls are in place within your environment.
- Update your Operating systems with this latest patch (MS10-001)
As always, some consideration is needed in order to evaluate any risks depending on whether you have the relevant affected environment. More details on these patches is given in the table below with links to the relevant Microsoft Knowledge base articles.
Table 1: Details of MS Patches released Tuesday 12/01/2010
| MS Link |
ITSL Summary |
Severity |
Affected Software |
Restart after patch |
|
MS10-001
KB972270
|
In simple terms this patch fixes a vulnerability that could allow an attacker to control and run code on your systems. Our advice is to patch desktops ASAP and Servers as part of your regular updates. |
Low
Critical
|
Windows 2000 (Critical), Windows XP, Windows 2003, Windows Vista, Windows 7 and Windows 2008 |
May Require Restart
|
| Rating |
Definition |
| Critical |
A vulnerability whose exploitation could allow the propagation of an Internet worm without user action. |
| Important |
A vulnerability whose exploitation could result in compromise of the confidentiality, integrity, or availability of users data, or of the integrity or availability of processing resources. |
| Moderate |
Exploitability is mitigated to a significant degree by factors such as default configuration, auditing, or difficulty of exploitation. |
| Low |
A vulnerability whose exploitation is extremely difficult, or whose impact is minimal. |