Microsoft released security bulletin 2639658 fixed malicious software Duqu use vulnerabilities
The Patch Tuesday and does not include Duqu malicious software disclosure of Windows kernel holes (CVE-2011-3402), but Microsoft’s rapid response team for this independent today released the security bulletin 2639658, and by using the Fix it button way to help users rapid repairing holes. The hole is from processing TrueType font embedding process problems, and attacker can view, changes, and delete data, and create have complete access to the account of, this is quite dangerous, means that the attacker can remote code execution (RCE) and privilege promotion (EOP).