Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Microsoft releases 14 patches, with nine rated as critical

by The Gurus
September 11, 2020
in Editor's News
Share on FacebookShare on Twitter

Microsoft released 14 security updates last night, nine of which were rated as critical.

Addressing 33 Common Vulnerabilities and Exposures (CVEs) in Windows, Internet Explorer, Office, .NET Framework and Remote Desktop Protocol.
Russ Ernst, director of product management at Lumension, said: “While we enjoyed a relatively low number of patches each month so far this year, November definitely takes a big jump up with 14 total bulletins released today: four are critical, eight important and two moderate.

“While this is two less than what we thought we would have today according to last week’s ANS, we still have to go back to September of last year for the last time Microsoft released this many bulletins in a single month. The good news however is the CVE count. Just 33 CVEs means fewer opportunities for the bad guys but because the software impacted is widespread, this Patch Tuesday is still a lot of work for IT.”

Since the patch was released, Microsoft revealed that MS14-064 should be the first priority patch as it is currently being exploited in the wild. This bulletin addresses 2 CVEs in a Windows OLE component that could allow a remote code execution.

Wolfgang Kandek, CTO of Qualys, said: “The most important bulletin, MS14-064, addresses a current 0-day vulnerability – CVE-2014-6352 in the Windows OLE packager for Vista and newer OS versions. Attackers have been abusing the vulnerability to gain code execution by sending PowerPoint files to their targets.

“Microsoft had previously acknowledged the vulnerability in security advisory KB3010060  and offered a work-around using EMET and a temporary patch in the form of a FixIt. This is the final fix for OLE Packager (Microsoft had patched the same software in October already with MS14-060 ) that should address all known exploit vectors.”

Craig Young, security researcher at Tripwire, said: “Some administrators may want to prioritise this over the Internet Explorer patch, even though we’ve seen attacks we’ve seen in the wild against the browser. This is because MS14-066 has the potential to be exploited without user-interaction.

“Fortunately Microsoft’s assessment is that reliable exploitation of this bug will be tricky. Hopefully, this will give admins enough time to patch their systems before we see exploits.”

Among other patches, Kandek recommened next looking at MS14-066, a patch for Internet Explorer that addresses 17 vulnerabilities. “The most severe of these vulnerabilities could be used to gain control over the targeted machine,” he said.

“An attack will take the form of a malicious webpage that the targeted user has to browse to. There are two basic scenarios that attackers use frequently: in the first the user browses to the site by their own volition, maybe as part of a daily routine, but the attacker has gained control over the website in question through a separate vulnerability and is able to plant malicious content on the site.”

Ross Barrett, senior manager of security engineering at Rapid7, said: “Every supported version of Windows is impacted by the critical issues, with the minor exception of Server Core not having Internet Explorer exposure. Perimeter systems are often mission critical and need the fastest attentions.  Administrators will have to balance the risk of exploit with their perceived exposure and their tolerance for downtime.”

Tags: MicrosoftMS14-064PatchesSecurity Update
ShareTweet
Previous Post

IT pros do not perform mobile security best practice

Next Post

Mircosoft Release Critical Patch As Vulnerability Is Found

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol