Microsoft quietly rolled out its ‘Patch Tuesday’ security package yesterday that brought with it four critical security updates that patch at least eight vulnerabilities in the various Windows operating systems and Office programs.
Among these, the most critical one, is a patch for Microsoft GDI, a specific component of Windows that is used to render JPGs and other image formats. The GDI component had no less than five separate vulnerabilities that could be exploited for malware installations by malicious images.
Other updates that were rolled out include a bug in virtually all versions of Office, that could lead to malicious code being triggered when a user clicks on a specially crafted OneNote link. The remaining security updates fix flaws in Windows Media Player and Windows Media Encoder which could also be used for security exploitation.
For further details on these security vulnerabilities please check out links here and here.