Microsoft patches new Windows bug exploited by Stuxnet
Microsoft today delivered nine security updates to patch 11 bugs in Office, the IIS Web server and Windows, including one that was overlooked but exploited by a July worm.
"Our old friend Stuxnet is back," said Jason Miller, data and security team manager for patch-management vendor Shavlik Technologies, referring to a worm that popped up two months as it attacked Windows computers used to manage industrial control systems in major manufacturing and utility companies.
"Vulnerability researchers decompiled the worm and found it was doing something else," Miller added. That something else was exploiting a vulnerability in Windows' print spooler service, a fact that experts at U.S. antivirus vendor Symantec and the Russian security firm Kaspersky Lab reported to Microsoft.