For July, Microsoft released 11 security bulletins, six of which were rated critical due to remote code execution (RCE) vulnerabilities. The worst flaws could allow RCE if a victim opens a malicious Office file. Microsoft said the more severe vulnerabilities could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application that could exploit the vulnerabilities. Qualys CTO Wolfgang Kandek said this should be a priority after deploying both browser, Office and Flash Player patches.”]

