News & Information for Technology Purchasers
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home Enterprise I.T. Hardware Software Communications More Topics...
Business Briefing
Average Rating:
Rate this article:  
Microsoft Patches New and Old Software Flaws Microsoft Patches New and Old Software Flaws
By Jennifer LeClaire
October 14, 2009 9:34AM

    Bookmark and Share
Microsoft's Patch Tuesday release includes new and old software vulnerabilities, and those marked critical allow remote code execution. That means computer restarts and a heavy workload for IT administrators. Analysts pointed to some Microsoft patches that are particularly important in Tuesday's release of security bulletins.
 

Advertisement

Microsoft Relevant Products/Services released its largest-ever batch of security Relevant Products/Services updates Tuesday, fixing 33 vulnerabilities in Windows, Internet Explorer, and other popular software. Eight of the updates are rated critical and five are rated important.

All the critical vulnerabilities are labeled as remote code execution, which would require system restarts and impact a very broad range of Windows platforms and applications, according to Lumension security and forensic analyst Paul Henry. But, he noted, IT administrators should pay attention to two particular security bulletins, as their vulnerabilities are being exploited in the wild: MS09-050 and MS09-053.

MS09-050 is a critical vulnerability that impacts both Vista and Windows 2008 platforms. While only rated as important, Henry said, MS09-053 should be considered a priority for organizations running public-facing FTP servers. He said organizations that use the Internet daily should also pay close attention to the high-priority critical client-side issues that could allow drive-by hacking exploits.

"Because of the large number of issues covered in this month's patch release, it is important that organizations carefully review the bulletin in its entirety and then carefully plan their patch-management priorities and process based on the impact on their given product utilization and the likelihood of exploitation," Henry said. "Simply put, the administrative burden of flaw remediation today is clearly beyond that which can be handled without full flaw-remediation process automation Relevant Products/Services."

Cleaning Up Old Messes

Andrew Storms, director of security operations for nCircle, has a different take. As he sees it, the bug that is likely to have the biggest impact on Microsoft users will be MS09-051, the speech-codec bug that already has limited exploits in the wild. This is a typical file-parsing issue and similar vulnerabilities have allowed attackers to create drive-by attacks that infect unsuspecting video viewers.

"MS09-056 isn't a critical vulnerability and it doesn't rate high on the exploitability index, but it does offer some insight into Microsoft security processes," Storms said. "Microsoft couldn't fix all the problems with nefarious Web SSL certifications, so they apparently reached out to all trusted root-certificate authorities to make sure they have a process that disallows signatures of null-byte certificates."

The SMB and IIS bugs, both acknowledged by Microsoft in early September, have received quite a bit of attention in the past month. The SMB vulnerability is difficult to exploit given default firewall Relevant Products/Services conditions, Storms noted, but the IIS bugs are easy to exploit. The risk for these vulnerabilities didn't warrant an out-of-band patch, he said, but are included in this month's whopper of a release.

Firefox Users At Risk

As a researcher who provides product content, Tuesday's release made Tyler Reguly, a senior security engineer at nCircle, very uncomfortable. The sheer size of the release and the tangle of vulnerabilities, he said, made it a long night for researchers everywhere looking for useful information for their customers.

"Again we see a month of client-side issues in almost every major Microsoft product. Whether you run Office, Windows Media Player, IE, .NET or just Windows itself, there's a vulnerability for you," Reguly said.

"Those with a Web-based attack vector are always important. Also this month, keep in mind that even Firefox users aren't safe from the IE vulnerability. There is a Firefox attack vector available, so patching IE should be considered crucial even if you never open it."
 

Advertisement


Advertisement


 Business Briefing
1.   Sony CEO Outlines Turnaround Plan
2.   Sony Ericsson Closes Sites, HQ Moves
3.   Intel Leads Retreat in World Markets
4.   MS Told To Stop Some Windows Sales
5.   Sources: MySpace May Buy imeem


advertisement
Multimedia E-Reader UnveiledMultimedia E-Reader Unveiled
Creative Labs prepares Mediabook.
Average Rating:
Vista More Secure Than Windows XPVista More Secure Than Windows XP
Windows 7 security could be expensive.
Average Rating:
Motorola's Droid Appears StrongMotorola's Droid Appears Strong
Early estimates put sales at 250,000.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Enterprise Hardware

  Go Green with IBM Blade Center
  

Network Security Spotlight
House Lawmakers Push Ban on Peer-to-Peer Software
Stung by an embarrassing electronic leak revealing ethics investigations into dozens of lawmakers, Congress moved to prohibit federal employees from using the file-sharing software blamed for the disclosure.
 
GAO: Los Alamos Computer Security Has Weaknesses
Security weaknesses uncovered in Los Alamos National Laboratory's computer network increase the risk of a classified-information breach, says the Government Accountability Office.
 
Computer Security Firm Fortinet Plans IPO This Week
Fortinet plans to go public in an initial public offering, giving investors a chance to tap a network security provider with sales that are expected to grow. The IPO could be valued at $137.5 million or more.
 

Enterprise Hardware Spotlight
Flat Shipments Hurt Dell Despite Increased Earnings
Dell's earnings are up and expectations are solid, but the company's stock still took a hit after analysts signaled the company isn't playing a key role in the PC market recovery.
 
New Pogoplug 'Personal Cloud' Does Social Networking
Cloud Engines has released its newest version of the Pogoplug, a small "multimedia sharing device" that connects hard drives to the Internet and allows a user to access the files remotely.
 
Apple Tablet Rumored Delayed as Publisher Gears Up
There have been so many rumors of an Apple tablet that it has taken on legendary status. But now the legend is being revised with reports of a delay and that a major publisher is getting ready.
 

Enterprise Technology Spotlight
Flat Shipments Hurt Dell Despite Increased Earnings
Dell's earnings are up and expectations are solid, but the company's stock still took a hit after analysts signaled the company isn't playing a key role in the PC market recovery.
 
Smartphones: A Bigger Target for Security Threats
Smartphones are increasingly prevalent and adept at handling more tasks, including trading stocks, paying bills, and buying stuff online. That makes them attractive to thieves and hackers.
 
FBI Says Hackers Targeting Law Firms, PR Companies
Hackers are targeting law firms and public relations companies with a sophisticated e-mail scheme that breaks into their computer networks to steal sensitive data, often linked to large corporate clients.
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Hardware | Software | Communications | Network Security | Wireless Tech | Linux/Open Source
Apple/Macintosh | Microsoft/Windows | World Wide Web | Data Storage | E-Commerce | Personal Tech | Tech Trends | Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2009 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo.