Sicurezza IT proattiva
 

One critical update for Microsoft systems in November 2011

2011-11-09 [Avvisi sul software]

In its security bulletin summary for November 2011 Microsoft has published one update for critical, two updates for important, and one update for moderate vulnerabilities in its operating systems / applications.

Critical is Microsoft's highest vulnerability rating.

A summary describing briefly the vulnerabilities is available from Microsoft's Security Bulletin Summary for November 2011.
From this page you will also find links to more detailed information in Microsoft's Security Bulletins MS11-083 - MS11-086.

The critical update addresses the following issue:

  • One privately reported vulnerability in TCP/IP. 

As expected Microsoft did not include any update for the recently discovered zero-day vulnerability in TrueType Font Parsing, which is used by Duqu. An out-of-band update for this is likely. Until a security update is available, Microsoft has published a workaround in the form of a fixit solution.

Updates that fixes the vulnerabilities addressed in the November bulletins are available from Windows automatic update mechanism.
To manually check for updates Click the Start button, click All Programs and then click Windows Update.

Norman advices all affected users to download the relevant security updates as soon as possible, to be protected from potential exploits.