Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Eight patches from Microsoft, but nothing for XP

by The Gurus
May 14, 2014
in Editor's News
Share on FacebookShare on Twitter

Microsoft released its heaviest patch bundle of 2014 last night, covering 13 vulnerabilities with eight bulletins.
 
Two of the bulletins are rated as critical and fix flaws in Internet Explorer and Sharepoint server. Wolfgang Kandek, CTO of Qualys, said that MS14-029 is top of the list and another surgical fix, similar to the out-of-band MS14-021 from May 1st. “MS14-021 addressed the zero-day CVE-2014-1776, which had been found in the wild by FireEye on April 26th,” he said.
 
“In a similar fashion MS14-029 addresses CVE-2014-1815, which was detected as having attacks in the wild by the Google Security Team. For good measure Microsoft also included MS14-021/CVE-2014-1776 in this bulletin, so if you have not installed it yet, you can just install MS14-029 and address both issues at the same time.”
 
Ross Barrett, senior manager of security engineering at Rapid7, said: “One of the other common vulnerabilities and exposures (CVEs) fixed in this advisory is under limited, targeted attack. Also, there are two flavours of this patch for Windows 8.1 users, one for those who took the ‘Spring 2014 update rollup’ and one for those who did not.
 
“Not to mention that this is the first advisory that clearly would have applied to Windows XP, but for which a patch is not available. IE 6, 7, & 8 are vulnerable on Windows 2003 SP2, this would historically have mapped to the same scope of XP patches, but not this time. Anyone still using XP just got a little less secure – not that they were well off to begin with.”
 
Looking at MS14-022, Russ Ernst, director of product management at Lumension, said: “Sharepoint users will want to pay close attention as it impacts 2007, 2010, 2013 and Microsoft Web Apps, otherwise known as Office Online. This one is for three CVEs, none under public attack, and they do require social engineering aimed at your users to trigger.”
 
Among the six “important” rated patches, Kandek said that MS14-024 and MS14-025 both provide fixes for issues that have been abused by malware, pen-testers and hackers alike. Ernst said that Ms14-026 is an elevation of privilege issue in Windows and the .NET framework, MS14-027 is a vulnerability in Windows Shell Handler that could allow an elevation of privilege. and MS14-028 is for 2 CVEs in iSCSI that could allow denial of service.
 
Tyler Reguly, manager of security research at Tripwire, said: “As a home user of Microsoft Office products, MS14-023 is very interesting to me. My family just migrated to Microsoft OneDrive and Office365 Home for all of our computing needs, and this vulnerability affects the passing of tokens in the OneDrive product; this means I’ll need to be hyper-vigilant in monitoring my families usage of these services until I can get the updates deployed across all of our computers.”
&nbs
p;
This is also the first month where no patches are issued for Windows XP. Kandek believed that any vulnerability for Windows Server 2003 is applicable to XP too, meaning that at least: MS12-029 (IE), MS12-024 (ASLR), MS12-025 (Group Profile), MS14-023 (not XP but Office 2003) patches will not be issued to XP.
 
“However, as we have seen, its market share is shrinking. If that tendency continues we will be close to zero per cent in another four months, even though we will probably see the inevitable flattening at the long-tail of the machine substitution,” he said.

Tags: ExplorerPatchVulnerabilityWindowsXP
ShareTweet
Previous Post

IETF plans to NSA-proof all future internet protocols

Next Post

Too good to be forgotten?

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol