Windows security update contains few, but vital, patches
This month’s Patch Tuesday update is, by Microsoft standards, fairly quiet. There is only one fix rated critical and one rated important, though the firm does warn both the associated vulnerabilities are at particular risk of exploitation.
The critical issue involves Microsoft’s XML Core Services features. These allow programmers to produce Windows applications based on XML. That’s a successor to HTML which allows programmers to create their own tags. Whereas HTML tags only affect they way information appears (for example as bold or an image caption), XML lets you organise data, for example marking a particular section of text as a recipe or a postal address.
The issue, which affects every currently supported version of Windows, would allow a hacker to execute code on a vulnerable machine, arguably the most serious attack which can be launched without physically accessing a computer. For those reasons, this is one of those patches which you really need to apply right away if you don’t use the automatic updates service.