Skip to main content

Microsoft addresses 23 flaws and additional Duqu-related attack vectors in May Patch Tuesday

Microsoft addresses 23 flaws and additional Duqu-related attack vectors in May Patch Tuesday

/

Microsoft has addressed 23 flaws across a number of its software products in the latest May Patch Tuesday.

Share this story

If you buy something from a Verge link, Vox Media may earn a commission. See our ethics statement.

wps_key
wps_key

Microsoft originally addressed a Duqu malware vulnerability around five months ago, but the company says it has patched additional attack vectors for the underlying root cause during this month's Patch Tuesday. There's seven bulletins in total to address 23 flaws across a variety of Microsoft products, leading to a busy Windows Update cycle for consumers and IT departments alike.

Microsoft's critical MS12-034 bulletin targets the vulnerable Duru-related code in particular, affecting all supported versions of Windows, Microsoft Office 2003, 2007, and 2010, alongside Silverlight 4 and 5. Microsoft .NET Framework 4 users will also be affected. The company says it's addressing the flaws in related products after its research team developed a "Cloned Code Detection" system to find any instance of the vulnerable code across multiple products. All the updates are now available on Windows Update.

Update: Microsoft has reached out to us to confirm that the company has not received any reports that indicate the attack vectors, addressed in MS12-034, have been publicly used to attack customers.

Today’s Storystream

Feed refreshed 44 minutes ago Not just you

T
Thomas Ricker44 minutes ago
The Simpsons pays tribute to Chrome’s dino game.

Season 34 of The Simpsons kicked off on Sunday night with an opening credits “couch gag” based on the offline dino game from Google’s Chrome browser. Cactus, cactus, couch, d’oh! Perfect.


T
Youtube
Thomas Ricker7:29 AM UTC
Table breaks before Apple Watch Ultra’s sapphire glass.

”It’s the most rugged and capable Apple Watch yet,” said Apple at the launch of the Apple Watch Ultra (read The Verge review here). YouTuber TechRax put that claim to the test with a series of drop, scratch, and hammer tests. Takeaways: the titanium case will scratch with enough abuse, and that flat sapphire front crystal is tough — tougher than the table which cracks before the Ultra fails — but not indestructible.


E
Twitter
Emma RothSep 25
Rihanna’s headlining the Super Bowl Halftime Show.

Apple Music’s set to sponsor the Halftime Show next February, and it’s starting out strong with a performance from Rihanna. I honestly can’t remember which company sponsored the Halftime Show before Pepsi, so it’ll be nice to see how Apple handles the show for Super Bowl LVII.


E
Twitter
Emma RothSep 25
Starlink is growing.

The Elon Musk-owned satellite internet service, which covers all seven continents including Antarctica, has now made over 1 million user terminals. Musk has big plans for the service, which he hopes to expand to cruise ships, planes, and even school buses.

Musk recently said he’ll sidestep sanctions to activate the service in Iran, where the government put restrictions on communications due to mass protests. He followed through on his promise to bring Starlink to Ukraine at the start of Russia’s invasion, so we’ll have to wait and see if he manages to bring the service to Iran as well.


Welcome to the new Verge

Revolutionizing the media with blog posts

Nilay PatelSep 13
E
External Link
Emma RothSep 25
We might not get another Apple event this year.

While Apple was initially expected to hold an event to launch its rumored M2-equipped Macs and iPads in October, Bloomberg’s Mark Gurman predicts Apple will announce its new devices in a series of press releases, website updates, and media briefings instead.

I know that it probably takes a lot of work to put these polished events together, but if Apple does pass on it this year, I will kind of miss vibing to the livestream’s music and seeing all the new products get presented.


E
External Link
Emma RothSep 24
California Governor Gavin Newsom vetoes the state’s “BitLicense” law.

The bill, called the Digital Financial Assets Law, would establish a regulatory framework for companies that transact with cryptocurrency in the state, similar to New York’s BitLicense system. In a statement, Newsom says it’s “premature to lock a licensing structure” and that implementing such a program is a “costly undertaking:”

A more flexible approach is needed to ensure regulatory oversight can keep up with rapidly evolving technology and use cases, and is tailored with the proper tools to address trends and mitigate consumer harm.


A
The Verge
Andrew WebsterSep 24
Get ready for some Netflix news.

At 1PM ET today Netflix is streaming its second annual Tudum event, where you can expect to hear news about and see trailers from its biggest franchises, including The Witcher and Bridgerton. I’ll be covering the event live alongside my colleague Charles Pulliam-Moore, and you can also watch along at the link below. There will be lots of expected names during the stream, but I have my fingers crossed for a new season of Hemlock Grove.