Microsoft patches two critical vulnerabilities for Windows and Internet Explorer

Microsoft's patch updates are crucial for admins
Microsoft's patch updates are crucial for admins

Microsoft has released six bulletins that address 29 vulnerabilities and three security advisories. The most critical bulletin, the MS14-037 update, will patch 24 Internet Explorer vulnerabilities that are deemed easy to exploit for potential attackers.

The most severe of the vulnerabilities listed in the MS14-037 update - or the Cumulative Security Update for Internet Explorer - could allow remote code execution if a user views a specially crafted web page using Internet Explorer, Microsoft said in its executive summary. Attackers who successfully exploit these vulnerabilities could gain the same administrative rights as the current user.

Wolfgang Kandek, Chief Technology Officer at Qualys says the critical patches in this update "all address vulnerabilities that could lead to remote code execution, which would allow an attacker to gain privileges on a machine by tricking a user to view a specially crafted Web page using the browser," in a statement.

Windows Journal

Microsoft has also released a critical update described by the company as "Vulnerability in Windows Journal Could Allow Remote Code Execution," which could allow remote code execution if a user opens a specially crafted Journal file.

This Windows Journal update is targeted for all versions of Windows Vista, Windows Server 2008 (excluding Itanium), Windows 7, Windows Server 2008 R2 (excluding Itanium), Windows 8, Windows Server 2012, Windows RT, Windows 8.1, Windows Server 2012 R2, and Windows RT 8.1.

The four additional bulletins are listed as important and moderate.

Latest in Pro
Hands typing on a keyboard surrounded by security icons
Outdated ID verification myths put businesses at risk
China
Chinese hackers targeting Juniper Networks routers, so patch now
Google Meet create custom backgrounds
More AI features are coming to Google Workspace
Google Chrome dark mode
Google updates Chrome extension rules to ban affiliate link injection without user action or benefit
Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard
This worrying botnet targets unsecure TP-Link routers - thousands of devices already hacked
Windows 10 button on a keyboard
Microsoft’s Remote Desktop app becomes the Windows App
Latest in News
Lilo & Stitch Official Trailer
Stitch crashes into earth and steals our hearts with the first trailer for the live-action Lilo & Stitch
GTA 5
GTA Online publisher Take-Two is gunning for a black market that’s basically heaven for cheaters
Y2K cast looking shocked
Y2K has a streaming release date on Max, so you can witness the technology uprising at home
The Discovery+ homepage
Discovery+ just got a big update to its streaming app that makes it more like Max – here are 5 great new features to try
Two Android phones on a green and blue background showing Google Messages
Struggling with slow Google Messages photo transfers? Google says new update will make 'noticeable difference'
China
Chinese hackers targeting Juniper Networks routers, so patch now