Microsoft's July Patch Tuesday to feature 2 critical fixes
Microsoft has notified users of upcoming security fixes, including two critical-rated vulnerabilities

Microsoft will be rolling out two critical fixes during its monthly Patch Tuesday round of security updates.
There are six notifications in all, with two ranked critical, three important and one listed as only moderate.
The average since 2013 has been around nine per month, so the six announced for next week represent a lower bulletin count than usual.
Of the two labelled critical, one is related to Internet Explorer, and is more than likely to be a patch that collects a number of updates needed to the browser. This marks the sixth Patch Tuesday in a row that's featured updates for the browser.
Wolfgang Kandek, CTO of Qualys, highlighted the importance of the IE update in a blog post. "This patch should be top of your list, since most attacks involve your web browser in some way.
"Take a look at the most recent numbers in Microsoft SIR report v16, which illustrate clearly that web- based attacks, which include Java and Adobe Flash are the most common," he added.
The second critical bulletin resolves remote code execution issues with all versions of Windows currently available, including Windows RT and RT 8.1.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Arriving third, fourth and fifth, the "important" bulletins address issues around privilege elevation. All the vulnerabilities addressed by these bulletins are local, meaning they cannot be executed through a network connection.
That doesn't mitigate the danger, claims Kandek, as an attacker who gains access to a computer through stolen credentials can still control the user's computer with them.
Bulletin six, ranked the lowest in importance with a "moderate" rating, fixes denial-of-service vulnerabilities in Microsoft's server software.
"All of the vulnerabilities in this month's release were discovered by Microsoft or privately disclosed by security researchers," said Karl Sigler, threat intelligence manager at Trustwave. "The good news is that none of these vulnerabilities have been exploited in the wild yet."
Full details of each bulletin will be released when the patches go live next Tuesday
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
Microsoft defends “negligent” security approach that prolonged vulnerability fix for five months
News The tech giant has refuted claims that its practices have left customers “in the dark”
By Ross Kelly Published
-
Ubuntu shifts to four-week update cycle
News Critical fixes will also come every two weeks, mitigating the issues involved with releasing prompt patches on the old three-week cadence
By Richard Speed Published
-
Microsoft angers admins as April Patch Tuesday delivers password feature without migration guidance
News Security fixes include a zero day exploited by a ransomware group and seven critical flaws
By Connor Jones Published
-
Motorola begins Stagefright patch roll-out
News 22 devices will be patched against the bug
By Jane McCallion Published
-
Google Chrome has highest number of vulnerabilities
News But the high level is down to its efficient detection system
By Clare Hopping Published
-
Apple issues Oracle Java 7 patch for Mac OS X users
News Consumer electronics giant hopes patch will fix zero-day Java exploit in Mac OS X.
By Rene Millman Published
-
Oracle issues ‘huge’ patch update
News A whopping 78 vulnerabilities are addressed in Oracle's latest CPU.
By Tom Brewster Published
-
Imperva CTO blasts Oracle patching
News Oracle's patching system needs fixing, according to Imperva's CTO.
By Tom Brewster Published