Over 30 flaws fixed in Microsoft’s biggest patch day
Windows, Internet Explorer and Office are patched up, but a DirectX flaw that hackers have been actively targeting isn’t.

Microsoft has released a big round of patches, with ten new security bulletins addressing a total of 31 vulnerabilities.
Symantec said the 31 flaws were the largest number of vulnerabilities addressed in a single release by Microsoft, with the previous record being 28 last December.
Of the 31 vulnerabilities, 17 were rated as critical. Six of the ten bulletins affected Windows, one of them Internet Explorer (IE), and three for Office (Word, Excel and Works).
Many security vendors agreed that the most significant bulletin was for IE, a cumulative update that addressed the first IE8 vulnerability.
The IE 8 vulnerability was found during the Pwn2Own hacking competition held in March, where a German researcher known as Nils exploited a flaw in a pre-release version of IE8.
The IE bulletin also fixed separate vulnerabilities across IE 6 and IE 7 for both XP and Vista, with other bulletins fixing an issue that allowed hackers to run code on a Mac running Powerpoint, as well as a server issue with Internet Information Services (IIS).
Microsoft has still not fixed a flaw in DirectShow QuickTime that hackers were actively exploiting at the beginning of this month.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
Adobe zero-day flaw code published
News A critical vulnerability for Adobe Shockwave Player has been discovered but no patch date has been confirmed.
By Tom Brewster Published
-
Microsoft issues emergency patch for shortcut loophole
News The software giant has been forced to step out of its normal Patch Tuesday cycle to address a vulnerability leaving all Windows PCs open to attack.
By Martin James Published
-
Adobe patch bypass found
News The fix released last week has not entirely solved the flaws in Adobe Reader.
By Jennifer Scott Published
-
Microsoft pulls ineffective server patch
News The patch doesn't fix the Windows 2000 Server problem 'effectively,' Microsoft said.
By Nicole Kobie Published
-
Microsoft issues out of band IE patch
News Microsoft has rolled out a series of patches ahead of schedule for its Internet Explorer browser.
By Nicole Kobie Published
-
Will there be an out-of-band update for latest IE flaw?
News Microsoft has confirmed it is working on a fix for yet another flaw in Internet Explorer, however it is remaining cagey about the release date.
By Jennifer Scott Published
-
Microsoft's out-of-band IE patch to arrive tonight
News Microsoft has rushed out a patch for a flaw in Internet Explorer.
By Nicole Kobie Published
-
Satio patch out but Carphone still not selling
News Although Sony Ericsson has released new firmware to fix problems with its Satio handset, Carphone Warehouse has yet to put it back on the shelves.
By Jennifer Scott Published