Microsoft, Adobe Plan Critical Patch Tuesday Security Updates

執筆者
Brian Prince
Brian Prince
Published: Aug 10, 2012
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Microsoft and Adobe Systems are planning to release security updates Aug. 14 to patch security holes in many of their enterprise applications.

Adobe released few details about the updates. According to the company, the updates will be for Adobe Reader and Acrobat X (10.1.3) and earlier 10.x versions for Windows and Macs. Adobe Reader and Acrobat versions 9.5.1 and earlier 9.x versions are affected for both operating systems as well. So far, no known exploits have been observed in the wild targeting any of the vulnerabilities slated to be fixed, the company said.

Microsoft meanwhile has plans to release nine security bulletins for its monthly Patch Tuesday update on Aug. 14. Five of the nine are rated critical.

“This month is a mixed bag of critical bulletins, which affects workstations, browser, server and productivity products,” said Marcus Carey, security researcher at Rapid7.

The five critical bulletins span a number of products: Windows, Internet Explorer, Microsoft SQL Server, Microsoft Exchange, Server Software and Developer Tools.

“Bulletin one is rated critical and will address Internet Explorer 6, 7 and 8,” Carey said. “Browser bulletins always deserve attention since client-side browser attacks are the de facto way to compromise corporate networks.”

The Exchange bulletin will address an issue Microsoft warned about in July regarding vulnerabilities in the way unstructured files are parsed by Oracle Outside In libraries. The situation affects Microsoft Exchange Server 2007, Exchange Server 2010 and FAST Search Server 2010 for SharePoint.

In the case of Exchange Server 2007 and Exchange Server 2010, it is possible under certain circumstances for an attacker to use the vulnerabilities to take control of the server process that is parsing a specially-crafted file. An attacker could then install programs or take any other action the server process has access to, according to Microsoft.

“Bulletin five is one to pay attention to since it addresses a critical remote code execution vulnerability in Microsoft Exchange,” Carey said.

“This is interesting from an exploitation standpoint because Exchange servers are usually exposed on the Internet. When attackers hear “remote code execution on Exchange” it’s music to their ears,” he said. “They could see potential for remote discovery, remote exploitation and propagation of attacks since Exchange is the epicenter of most organizations’ communications. Email servers are prime targets for exploitation.”

Advertisement

The other four bulletins address issues in Windows and Office. The Patch Tuesday updates are slated to be released at 10 a.m. PDT.

Brian Prince

Brian Prince

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。