Proactive IT Security
 

Three critical updates for Microsoft systems in July 2010

2010-07-13 [Software advisories]

In its security bulletin summary for July 2010 Microsoft has published three updates for critical and one update for important vulnerabilities in its operating systems / applications.

Critical is Microsoft's highest vulnerability rating.

A summary describing briefly the vulnerabilities is available from Microsoft's Security Bulletin Summary for July 2010.
From this page you will also find links to more detailed information in Microsoft's Security Bulletins MS10-042- MS10-045.

The critical updates address the following issues:

  • One publicly disclosed vulnerability in the Windows Help and Support Center feature that is delivered with supported editions of Windows XP and Windows Server 2003. We also refer to Norman's Security Advisory 11 June - this vulnerability has been actively exploited.
  • One publicly publicly disclosed vulnerability in the Canonical Display Driver (cdd.dll). .
  • Two privately reported vulnerabilities in Microsoft Office Access ActiveX Controls.

Updates that fixes the vulnerabilities are available from Windows automatic update mechanism for systems that support this. Alternatively, one may download updates from http://windowsupdate.microsoft.com.

Norman advices all affected users to download the relevant security updates as soon as possible, to be protected from potential exploits.