|
|
|
You are here: News > News > Fix for two security holes on Microsoft’s May update
| » IT Security NEWS |
| » 08 May 2010 |
| Fix for two security holes on Microsoft’s May update |
Microsoft Corporation’s scheduled monthly update will be held on the 11th of May and the company released their advance notification to announce that two critical threats in the Windows OS and Microsoft Office will be patched up on the same date. Based on the blog post created by Jerry Bryant, Microsoft’s group manager for response communication, the two vulnerabilities that they discovered lets hackers activate malicious codes even from a given distance.
Using of factory settings will keep users safe
The update will be available for the users of both Microsoft products Windows 7 and Windows Server 2008 R2. However, Bryant said that the consumers will not be in danger only if they remained using the default settings of these merchandises.
Even with a scheduled update, the company will not include in the pack the remedy for the vulnerability found in SharePoint. The manufacturer is still trying its best to find a way to solve this problem in their product.
Use of strategic methods is necessary
Microsoft suggested that the managers of the different agencies making use of SharePoint should just utilize the access control list to the SharePoint Help.aspx. This will avoid any unlawful entry of the abusive users into the vulnerable components of the product. The staff may also try deactivating some of the features of the Internet Explorer for additional protection.
Alan Bentley, the vice president of the security firm Lumension, added that a fix patch for the SharePoint will be available for the users in no time. He added that the remedy for this security hole will most likely be included in this month’s out-of-band patch.
Bentley believed that the vulnerability has a very sensitive characteristic that it allows cross-site scripting. Thus, the confidential information of the company that is located in the enterprise content management system might be put in danger.
Upgrading the software may also ensure safety
As always, Microsoft repeated its announcement regarding the end of distribution of the updates for Windows 2000 and Windows XP SP2. As noted by the company, updates for these merchandises will stop on the 13th of July year 2010. Hence, there is a great need to use an advanced version of operating systems or utilize the more recent service pack so as to receive continuous security updates.
Read useful information through the following SecPoint links: About SecPoint, SecPoint Press, and SecPoint Awards. |