Guess what today is? Yes, it is Fat Tuesday--the official kick off of Mardi Gras. But, it's also Patch Tuesday. Again. The good news is that there are only three security bulletins--only one of which is rated Critical. The bad news is that the Critical flaw will be very easy for attackers to exploit. Guess what today is? Yes, it is Fat Tuesday–the official kick off of Mardi Gras. But, it’s also Patch Tuesday. Again. The good news is that there are only three security bulletins–only one of which is rated Critical. The bad news is that the Critical flaw will be very easy for attackers to exploit.The main concern this month is MS11-015, which addresses two separate vulnerabilities. The security bulletin explains that the more severe vulnerability could be exploited to allow an attacker to execute malicious code remotely. The good news is that triggering the vulnerability requires some action on the part of the user. But, social engineering attacks related to video clips are common, and often relatively successful.“The lone critical issue this month – the DVR-MS vulnerability – will be somewhat trivial for attackers to exploit,” said Joshua Talbot, security intelligence manager, Symantec Security Response. “It also allows attackers to skip a few of the traditional steps needed to get malicious code to execute on a targeted computer. This is because when processing DVR-MS files, Windows Media Player and Media Center use data in these files themselves to determine what code in memory gets executed. This allows an attacker to jump directly to executing malicious code.”As for the other two March security bulletins, there isn’t much to see. Tyler Reguly, technical manager of security research and development for nCircle, says, “DLL Preloading is such a snooze it’s really not worth talking about anymore.” Notably absent from the Patch Tuesday lineup is a fix for the MHTML flaw discovered in late January. It was expected that it wouldn’t make the cut for last month’s Patch Tuesday updates because of the short notice. But, with over a month to analyze the bug and develop a patch, it was expected that Microsoft would resolve the problem this time around.Andrew Storms, director of security operations for nCircle, points out that April could bring another avalanche of patches and updates. “CanSec West’s Pwn2own hacking contest is also scheduled for later this week and that traditionally unearths some interesting Internet Explorer and Windows 7 phone security bugs.” As always–whether Microsoft releases two security bulletins, or twelve–Microsoft and security experts all recommend that any applicable patches and updates be applied as soon as possible. Attacks against zero-day vulnerabilities grab headlines, but frequently malware targets known vulnerabilities that vendors have already deployed patches for, but customers haven’t applied the updates. Related content news analysis Companies are already feeling the pressure from upcoming US SEC cyber rules New Securities and Exchange Commission cyber incident reporting rules don't kick in until December, but experts say they highlight the need for greater collaboration between CISOs and the C-suite By Cynthia Brumfield Sep 28, 2023 6 mins Regulation Data Breach Financial Services Industry news UK data regulator warns that data breaches put abuse victims’ lives at risk The UK Information Commissioner’s Office has reprimanded seven organizations in the past 14 months for data breaches affecting victims of domestic abuse. By Michael Hill Sep 28, 2023 3 mins Electronic Health Records Data Breach Government news EchoMark releases watermarking solution to secure private communications, detect insider threats Enterprise-grade software embeds AI-driven, forensic watermarking in emails and documents to pinpoint potential insider risks By Michael Hill Sep 28, 2023 4 mins Communications Security Threat and Vulnerability Management Security Software news SpecterOps to use in-house approximation to test for global attack variations The new offering uses atomic tests and in-house approximation in purple team assessment to test all known techniques of an attack. By Shweta Sharma Sep 28, 2023 3 mins Penetration Testing Network Security Security Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe