
<A HREF="http://www.eweek.com/article2/0,1759,2214884,00.asp?kc=EWRSS03119TX1K0000594">Patch Tuesday will bring two security bulletins</A> from Microsoft, one of which is critical and involves a remotely exploitable hole on Windows systems, the other of which is rated important and also affects Windows. eEye's Zero-Day Tracker, as of Nov. 9, is listing three active zero-day Windows and Internet Explorer vulnerabilities, all of which have been publicly disclosed and/or used in attacks, none of which have been patched.
The critical patch promised for the Nov. 13 Patch Tuesday could well be a flaw in a Macrovision driver on Windows XP and Windows 2003. That vulnerability was actively being exploited in the wild as of Nov. 5, when Microsoft sent a special security advisory to warn customers of the danger of complete system takeover.