Microsoft has issued an advanced notification for the next Patch Tuesday, which falls on February 8. This month's patch cycle includes 12 security bulletins, three of which are ranked "critical," Microsoft's highest severity rating, while the remaining nine are classified "important." In all, 22 vulnerabilities will be fixed, including several that allow an attacker to gain control of Windows.
Among the addressed flaws is one associated with a CSS function in Internet Explorer that could lead to the execution of arbitrary code by visiting an attacker's web page. Notably absent is a fix for the cross-site scripting vulnerability in MHTML that affects all supported versions of Windows, though Microsoft has provided a workaround (scroll down and expand Mitigating Factors and Suggested Actions for more info):
- Enable the MHTML protocol lockdown.
- Set Internet and Local intranet security zone settings to "High" to block ActiveX Controls and Active Scripting in these zones.
- Configure Internet Explorer to prompt before running Active Scripting or to disable Active Scripting in the Internet and Local intranet security zone.
Virtually all of Microsoft's supported operating systems will receive a patch, from Windows XP SP3 and Server 2003 SP2 through Windows 7 and Server 2008 R2. Internet Explorer 6, 7 and 8 are listed more than once, while affected Office software is limited to Visio 2002, 2003 and 2007. As usual, Microsoft will host a webcast to address customer questions on February 9 at 11AM Pacific. Oh, and nearly all of the bulletins call for a reboot, so heads up on that.