MICROSOFT HAS RELEASED the first batch of security updates for 2016, and they include critical fixes for remote code execution flaws in Windows, Office, Edge, Internet Explorer, Silverlight, and Visual Basic.
The company has also fixed remote code execution and elevation of privilege vulnerabilities in Windows, and an address spoofing flaw in Exchange Server, that were rated important, not critical, due to various mitigating factors.
In total, Microsoft issued 9 security bulletins (go.pcworld.com/msbulletins) covering patches for 24 vulnerabilities.
According to Wolfgang Kandek, the CTO of security firm Qualys, administrators should prioritize the MS16-005 security bulletin, especially for systems running Windows Vista, 7, and Server 2008.
This patch addresses a remote code execution vulnerability tracked as CVE-2016-0009 that has been publicly disclosed, making attacks more likely.
The second most important bulletin,…