Microsoft has again this month issued a security patch before their usual round of monthly releases. Microsoft typically only releases these "out-of-cycle" patches when hackers are exploiting the flaw in real-world attacks and as a result we consider these to be important patches to apply.
This patch is classed as Critical and fixes multiple reported vulnerabilities in all versions of Internet Explorer.
Our advice is…
- Ensure that the critical patch is deployed to all affected Windows desktop and server operating systems immediately.
- Ensure that all Anti-virus and Malware blocking software packages are fully up to date, and properly configured firewalls are in place within your environment.
In summary…
- Update your Desktop and Server computers immediately with the critical patches (MS10-018).
- Please also make sure that all additional IT Security solutions (Anti Virus, Anti Malware and Firewall) are in place, are up to date and are appropriate for your environment.
Table 1: Details of MS Patches released Thursday 30/03/2010
| MS Link |
ITSL Summary |
Severity |
Affected Software |
Restart after patch |
| MS10-018 |
This patch is an emergency ‘out of band’ release to deal with the reported security vulnerabilities in all supported versions of Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer.
|
Critical |
Internet Explorer 5, 6, 7 & 8
|
Yes |
| Rating |
Definition |
| Critical |
A vulnerability whose exploitation could allow the propagation of an Internet worm without user action. |
| Important |
A vulnerability whose exploitation could result in compromise of the confidentiality, integrity, or availability of users data, or of the integrity or availability of processing resources. |
| Moderate |
Exploitability is mitigated to a significant degree by factors such as default configuration, auditing, or difficulty of exploitation. |
| Low |
A vulnerability whose exploitation is extremely difficult, or whose impact is minimal. |