Weekly Infosec New Brief 13-19 April

Microsoft "Patch Tuesday" Includes Eleven Patches, Four of Them Critical

Last Tuesday, Microsoft released their monthly batch of updates. This time there were four critical updates out of eleven total, though many of the updates address multiple vulnerabilities. The most critical of these is MS15-033, which addresses an Office vulnerability that could enable a malicious document to run code on the vulnerable system. It is believed that this flaw is being actively exploited already. The other patch that should be expedited is MS-034, which involves a vulnerability in the IIS web service on Windows 2008R2 and 2012. This flaw is also being actively exploited by attackers to crash web serves on the Internet. If your organization is running a Windows-based web server, consider testing and implementing this patch as quickly as possible.
https://technet.microsoft.com/library/security/ms15-apr?f=255&MSPPError=-2147217396
http://www.symantec.com/connect/blogs/microsoft-patch-tuesday-april-2015


Adobe Releases Multiple Patches, Including One for a Critical Flash Zero-Day

Last Tuesday, Adobe release security notices for three products, Flash, ColdFusion, and Flex. The Flash vulnerability is critical and it is believed that this vulnerability is being actively exploited on the Internet already. It is possible for a malicious website to run unauthorized code on vulnerable systems if a user visits a malicious website, or even one containing a malicious advertisement.
https://helpx.adobe.com/security/products/flash-player/apsb15-06.html


Oracle Releases a Whopping 98 Security Bulletins, Including Final Java 7 Update

Oracle released a large collection of updates last week for a variety of products, including Java, Oracle, MySQL, and many others. Three of the Java patches are for critical vulnerabilities (CVE-2015-0469, CVE-2015-0459, and CVE-2015-0491), and should be applied as quickly as possible. This update is also the last update that will be made to Java 7; organizations should check to see if they are running Java and upgrade any systems that are to Java 8.
http://www.symantec.com/connect/blogs/microsoft-patch-tuesday-april-2015
https://blogs.oracle.com/security/
https://www.java.com/en/download/faq/java_7.xml

Comments

Popular posts from this blog

Weekly Infosec News Brief: 14-20 March

Weekly Infosec News Brief 20-26 July

Weekly Infosec News Brief: 22-28 February