Microsoft Starts 2014 With Four Security Advisories
For the first time in more than a year, Microsoft is not including an Internet Explorer patch in a Patch Tuesday update. Is that a cause for concern?
Microsoft is out today with its first Patch Tuesday security update for 2014, issuing four security bulletins that address six different Common Vulnerabilities and Exposures (CVE) issues in Windows, Office and Dynamics AX.
All four of the bulletins are rated as having "high" importance, which is one level below "critical." The MS14-001 bulletin details three CVEs in Microsoft Office that could potentially enable remote code execution. The MS14-002 and MS14-003 bulletins each provide a fix for Windows kernel-related vulnerabilities that could potentially have enabled an unauthorized privilege escalation.
The final bulletin is MS14-004, which provides a fix for a denial-of-service (DoS) vulnerability with Microsoft's Dynamic AX.