FESTIVE INDULGENCES took their toll on Microsoft's security team after they managed to fix just four security flaws during December in time for the first Patch Tuesday security release for 2017.
Whereas most releases usually contain anywhere from 30 to 60 fixes, the January release is far lower, with three rated Important and just one as Critical. It must have been some Christmas party.
The critical fixed, termed MS17-003, fixed problems in Flash that affects many major versions of Windows, as Microsoft outlined.
"This security update resolves vulnerabilities in Adobe Flash Player when installed on all supported editions of Windows 8.1, Windows Server 2012, Windows Server 2012 R2, Windows RT 8.1, Windows 10, and Windows Server 2016."
The Important fixes are for Windows, Edge, Office and Flash player again, with Microsoft warning that they pose a risk should attackers use the flaws.
"The vulnerability could allow remote code execution if a user opens a specially crafted Microsoft Office file," reads the notes for the flaw in Office.
"An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. Customers whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights."
Commenting on the latest release Amol Sarwate, director of Vulnerability Labs, Qualys, said the fact it was such a small update would "definitely make system administrators happy" but that it was worth acting on the patches nonetheless.
"Overall, it's a very light patch update for administrators with one unauthenticated DoS for Server 2008 and one critical Word 2016 remote code execution vulnerability for workstations," he wrote in a blog post.
The low fix count contrasts with Google which last week rolled out 50 fixes for Android as part of its recently launched initiative to provide faster updates for its mobile platform. Clearly no such festivities at Google. µ
Oh and it'll also help give aural pleasure
But it might still not be enough to make virtual reality super appealing
And a ridiculous competition
Now you can talk to your silly-looking earbuds too