Microsoft released seven security bulletins addressing 26 unique vulnerabilities in Microsoft Windows, Internet Explorer, and other applications as part of June's Patch Tuesday release on June 12. The company separately announced changes to its automatic updater to block untrusted security certificates. Microsoft updated the updater tool after researchers at Kaspersky Lab uncovered how the Flame malware had gamed the process.
Of the three "critical" and four "important" bulletins, security experts agreed that administrators should prioritize the Internet Explorer and Remote Desktop Protocol updates. The Internet Explorer update (MS12-037) affects versions 6, 7, 8, and 9, and "as usual it's the one to patch first," said Andrew Storms, director of security operations at nCircle. Limited exploits for this IE bug have already been observed in the wild, according to Microsoft.
|