Microsoft addresses 23 flaws and additional Duqu-related attack vectors in May Patch Tuesday


Microsoft originally addressed a Duqu malware vulnerability around five months ago, but the company says it has patched additional attack vectors for the underlying root cause during this month's Patch Tuesday. There's seven bulletins in total to address 23 flaws across a variety of Microsoft products, leading to a busy Windows Update cycle for consumers and IT departments alike.

Microsoft's critical MS12-034 bulletin targets the vulnerable Duru-related code in particular, affecting all supported versions of Windows, Microsoft Office 2003, 2007, and 2010, alongside Silverlight 4 and 5. Microsoft .NET Framework 4 users will also be affected. The company says it's addressing the flaws in related products after its research team developed a "Cloned Code Detection" system to find any instance of the vulnerable code across multiple products. All the updates are now available on Windows Update.

Update: Microsoft has reached out to us to confirm that the company has not received any reports that indicate the attack vectors, addressed in MS12-034, have been publicly used to attack customers.

The Verge
Log In Sign Up

Log In Sign Up

Forgot password?

We'll email you a reset link.

If you signed up using a 3rd party account like Facebook or Twitter, please login with it instead.

Forgot password?

Try another email?

Almost done,

By becoming a registered user, you are also agreeing to our Terms and confirming that you have read our Privacy Policy.



Choose an available username to complete sign up.

In order to provide our users with a better overall experience, we ask for more information from Facebook when using it to login so that we can learn more about our audience and provide you with the best possible experience. We do not store specific user data and the sharing of it is not required to login with Facebook.