We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message
78,131 News Articles

Critical Windows updates coming next week

But no fix for new Word exploit

Microsoft plans to patch its Windows and Visual Studio products next week, but it doesn't have a fix in the works for a widely publicised flaw in Word, which hackers are reportedly exploiting in targeted attacks.

The company's security team is readying five sets of patches for Windows, and will also issue a single critical security update for Visual Studio.

Microsoft rates the most serious of its Windows updates as "critical", meaning an attacker could exploit the underlying flaw to run malware on a victim's PC with no user action.

These security patches are usually released on the second Tuesday of each month, and the company strives to publish a small number of updates in December, because IT operations are often short-staffed during the holiday season.

On Tuesday, Microsoft warned of vulnerability in its Word software that had been reportedly used in online attacks. Security researchers rated this flaw critical, because an attacker could exploit it to run malicious software on a victim's PC. For such an attack to work, however, the victim would first have to be tricked into opening a maliciously encoded Word file.

The Word flaw is not scheduled to be patched next Tuesday, said a spokesperson for Microsoft's public relations firm.

There is, however, one critical Visual Studio flaw that may be addressed in the updates. That bug is in Visual Studio 2005's WMI Object Broker ActiveX object. It was first reported in late October.


IDG UK Sites

OnePlus Two release date rumours: Something's happening on 22 July

IDG UK Sites

13in MacBook Air review, Apple's MacBook Air 2014 reviewed

IDG UK Sites

5 reasons to buy an electric car and 5 reasons not to

IDG UK Sites

Evernote Skitch: the best way for creatives to doodle feedback