Microsoft's 'dirty dozen' security patches

Microsoft's second 'Patch Tuesday' this year includes two patches for Microsoft Office, one of them critical

Microsoft is to release 12 security patches on Tuesday, 13 February. Several are critical.

This year's second 'Patch Tuesday' includes five patches for Windows, and at least one of them is critical, according to Microsoft.

Two patches for the Microsoft Office suite are also included, again with the most serious being labelled critical.

The rest of the security patches address issues in Microsoft Visual Studio , Step-by-Step Interactive Training, Microsoft Data Access Components , and various security tools such as the Windows Live OneCare package, and its Windows Defender anti-spyware.

At least four of these are also labelled as critical, Microsoft's highest severity rating. Microsoft's definition of a critical update is that it fixes a vulnerability which may be exploited with no, or very little, action by the user.

14 known, un-patched, holes

Microsoft provided no further details on which problems it is fixing, other than that some of the updates may require a system restart.

There are 14 known, but yet to be patched, security holes in various Microsoft products, according to the Internet Storm Center (ISC) , a co-operative monitoring and alert system of cyber threats, which keeps a list of Microsoft bugs that need to be patched. At least five of those affect Microsoft Office, and at least one can be found in Microsoft Visual Studio.

"It'll be great if [Microsoft] fixes the right ones," said Johannes Ullrich, chief technology officer for the ISC, who noted that next week's release will be one of the company's larger security updates.

"Last month, they didn't fix any outstanding Office bugs, and they're high-value targets. It's important to get them fixed," Ullrich said.

The security updates will be available to download manually from Microsoft's website from Tuesday. Automatic updates will be sent out to users' PCs shortly after that.

TOPICS
Latest in Computing Security
Dark Web monitoring
How users benefit from Dark Web monitoring
The X logo next to a silhouette of Elon Musk
Who was really behind the massive X cyberattack? Here’s what experts say about Elon Musk’s claims
A person holding a phone looking at a scam text with warning signs around
A massive SMS toll fee scam is sweeping the US – here’s how to stay safe, according to the FBI
View on National Assembly building in Paris, France, with French and European flags flying.
France rejects controversial encryption backdoor provision
ensure data security for your business
The complete data protection system for your business
ignal messaging application President Meredith Whittaker poses for a photograph before an interview at the Europe's largest tech conference, the Web Summit, in Lisbon on November 4, 2022.
"We will not walk back" – Signal would rather leave the UK and Sweden than remove encryption protections
Latest in News
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras
Security padlock and circuit board to protect data
Trust in digital services around the world sees a massive drop as security worries continue
A Lego Pikachu tail next to a Pebble OS watch and a screenshot of Assassin's Creed Shadow
ICYMI: the week's 7 biggest tech stories from LG's excellent new OLED TV to our Assassin's Creed Shadow review
Samuel and Romy standing very close together in A24's Babygirl movie
Everything new on Max in April 2025, including A24's Babygirl and The Last of Us season 2
An AMD Radeon RX 9070 XT made by Sapphire on a table with its retail packaging
AMD’s secret weapon against Nvidia seems to be stock – way more RX 9070 GPUs are rumored to be hitting shelves than RTX 5000 models
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks