Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Final Microsoft updates sees re-released patches and three critical fixes

by The Gurus
December 10, 2014
in Editor's News
patch
Share on FacebookShare on Twitter

Microsoft released seven security updates last night, with three rated as critical and re-released patches issued for Explorer and Schannel flaws.
 
Russ Ernst, director of product management at Lumension, said that the re-release of MS14-066 and MS14-065, which were originally released in November, gives users the opportunity to re-apply them due to the change in package, especially as the “Schannel” vulnerability proved to be a bit of a problem-child for some IT departments last month when Microsoft revised the bulletin to include support for Windows Server 2008 R2 and Windows Server 2012.
 
Craig Young, security researcher at Tripwire, said: “Many frustrated admins still suffering from ill-effects from Microsoft’s botched (but critical) SChannel update will be getting an early Christmas present this year with a re-release of the MS14-066 patch. Initially released last month, the patches  caused a variety of TLS connection woes.  With denial-of-service exploit code available, it’s critical that all systems receive this patch ASAP.
 
“This issue can be exploited with an HTTPS request or remote desktop connection providing a maliciously crafted certificate for authentication.  Unlike other RDP vulnerabilities disclosed in recent years, the use of NLA does not mitigate this vulnerability at all because it’s exploited during the SSL/TLS handshake.  The only saving grace for enterprises is that achieving reliable code execution is not a trivial task.”
 
This month’s patch bundle covers 24 common vulnerabilities and exploits (CVE). Ernst said: “In December, IT efforts will largely focus on the desktop. There are 24 CVEs to be covered off in December, none under active attack at this point. First on your list of priorities should be the cumulative update for all versions of Internet Explorer in MS14-080. This includes fixes for 14 CVEs of which one CVE is shared with another critical ranked bulletin, MS14-084 for a vulnerability in VBScript.”
 
Karl Sigler, threat intelligence manager at Trustwave, said: “This security update resolves fourteen privately reported vulnerabilities in Internet Explorer. The most severe of these vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the current user. Customers whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.
 
“This security update affects Internet Explorer 6 through Internet Explorer 11 on affected Windows cl
ients and servers.”

 
MS14-081 is also marked Critical. Ross Barrett, senior engineering manager at Rapid7, said: “In most cases this type of issue would only be important, because typically a document format use-after-free issue requires user interaction to exploit, but in this case because of the potential for exploitation through Sharepoint Web Apps the risk is greater.”
 
The final critical patch is MS14-084, a vulnerability in the VBScript scripting engine which could allow remote code execution. Sigler said: “This vulnerability could allow remote code execution if a user visits a specially crafted website with Internet Explorer. It could also be exploited via a specially crafted Office document designed to invoke the IE rendering engine. The security update addresses the vulnerability by modifying how the VBScript scripting engine handles objects in memory.
 
“This security update is rated Critical for affected versions of the VBScript scripting engine on affected Windows clients and Moderate for affected versions of the VBScript scripting engine on affected Windows servers.”
 
Also released this month, and delayed from November is MS14-075 covering four CVEs in all supported versions of MS Exchange. Barrett said: “This patch addresses two Outlook Web Access Cross Site Scripting issues, a web application token spoofing issue, and an issue with Exchange URL redirection.
 
“Even though only tagged important, the presence of MS Exchange on the perimeter and the potential for this type of attack to be combined with stolen credentials and other malicious behaviour will make it a patching priority.”

Tags: MicrosoftPatchVulnerabilityWindows
ShareTweet
Previous Post

Businesses fail to balance employee access and security demands

Next Post

Tripwire set to be acquired for $710 million

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol