Microsoft fixes 'critical' Windows flaws

The latest patches follow Microsoft's monthly 'Patch Tuesday' update cycle

Windows has been patched again after Microsoft released three new critical updates, plus two others of lesser importance. Such fixes are classified as critical when the problem might allow a hacker to gain control of a user's PC without the user actually doing anything themselves.

This is usually through the release of a worm or "remote code execution" that can self-replicate, without the need to rely on user action.

Windows Vista is among the Windows versions affected, along with XP, 2000 and Server 2003.

Of the two non-critical patches, one was for Microsoft's Content Management Server operating system; the other for Windows. Both are classified at the lower threat level of 'important'. If you have Automatic Updates turned on, you'll get the updates dripped down to you. They can also be manually downloaded .

These latest patches follow Microsoft's monthly 'Patch Tuesday' update cycle. But last week, the corporation had to issue an extra update after the exposure of a critical flaw affecting animated cursors . Microsoft has released a further version of this patch in this latest round of updates as some users found last week's patch conflicted with apps on their system.

The reason for the extra update was that the cursor vulnerability was rapidly being exploited, so Microsoft decided to act . The weakness occurred in the way Windows handles .ani files, a format that manages animated cursors and icons. When the file opens, a memory flaw can occur. The flaw can be exploited by luring a user to a malicious website, opening a manipulated email message or a virus-infested attachment. A successful attack gives the hacker full control of the computer.

"Over this weekend attacks against this vulnerability have increased somewhat," programme manager Christopher Budd wrote on Microsoft's Security Response Center blog last week. Microsoft originally posted a warning about the security threat on 31 March.

TOPICS
Contributor

Dan (Twitter, Google+) is TechRadar's Former Deputy Editor and is now in charge at our sister site T3.com. Covering all things computing, internet and mobile he's a seasoned regular at major tech shows such as CES, IFA and Mobile World Congress. Dan has also been a tech expert for many outlets including BBC Radio 4, 5Live and the World Service, The Sun and ITV News.

Latest in Software & Services
TinEye website
I like this reverse image search service the most
A person in a wheelchair working at a computer.
Here’s a free way to find long lost relatives and friends
A white woman with long brown hair in a ponytail looks down at her computer in a distressed manner. She is holding her forehead with one hand and a credit card with the other
This people search finder covers all the bases, but it's not perfect
That's Them home page
Is That's Them worth it? My honest review
woman listening to computer
AWS vs Azure: choosing the right platform to maximize your company's investment
A person at a desktop computer working on spreadsheet tables.
Trello vs Jira: which project management solution is best for you?
Latest in News
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Hatch Restore 3 in Putty
You can finally start your day with The Office theme song, and I couldn't be more excited
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
Ncuti Gatwa as The Fifteenth Doctor in Doctor Who
Disney+ drops new trailer for Doctor Who season 2 that promises an epic adventure across time and space
23andMe
23andMe is bankrupt and about to sell your DNA, here's how to stop that from happening