Microsoft to issue single patch next week
Microsoft will launch a fix for a Powerpoint exploit next week during its Patch Tuesday update cycle.

Breaking recent security tradition, Microsoft is planning to release a single patch next week as part of its Patch Tuesday update cycle.
The update is for an issue recently discovered within PowerPoint.
Although the issue was identified in April, this is the first time that it will have been patched. Last month, the firm used its Patch Tuesday to release eight updates that patched 23 vulnerabilities, making this month's single release seem somewhat insignificant.
However it is not. Microsoft described the issue in PowerPoint - versions 2000, 2002, 2003 and 2007- as critical, its highest possible severity warning.
Microsoft describes issues as 'critical' when the vulnerability is so severe that its exploitation could allow for the 'propagation of an internet worm without user action'. In its security update notification, the firm adds: "We believe that customers who use an affected product should almost always apply patches that address vulnerabilities rated critical or important."
Microsoft added: "For Microsoft Office PowerPoint 2007 Service Pack 1 and Microsoft Office PowerPoint 2007 Service Pack 2, customers also need to install the security update for Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 1 and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 2 to be protected from the vulnerabilities described in this bulletin."
While no other vulnerability patches are planned, Microsoft added that it would be releasing an updated version of its Windows Malicious Software Removal Tool as well as a number of other non-critical updates.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The patch is expected to be released on 12 May.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd
-
Vulnerability management complexity is leaving enterprises at serious risk
News Fragmented data and siloed processes mean remediation is taking too long
By Emma Woollacott
-
Beat cyber criminals at their own game
Whitepaper A guide to winning the vulnerability race and protection your organization
By ITPro
-
Same cyberthreat, different story
Whitepaper How security, risk, and technology asset management teams collaborate to easily manage vulnerabilities
By ITPro
-
Three steps to transforming security operations
Whitepaper How to be more agile, effective, collaborative, and scalable
By ITPro
-
Should your business start a bug bounty program?
In-depth Big tech firms including Google, Apple and Microsoft offer bug bounty programs, but can they benefit smaller businesses too?
By Kate O'Flaherty
-
Accessing the XDR realm
Whitepaper A guide for MSPs to unleash modern security
By ITPro
-
Why zero trust strategies fail
In-depth Zero Trust is the gold standard for organizations in protecting systems from cyber attacks, but there are many common implementation pitfalls businesses must avoid
By Sandra Vogel
-
Sitecore XP RCE flaw is being actively exploited, ACSC warns
News The vulnerability was fixed last month but hackers are now moving against patching laggards
By Rene Millman