Newsletters
News & Information for Technology Purchasers NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
Home Enterprise I.T. Cloud & Virtualization Applications Unified Communications More Topics...
Build Apps 5x Faster
For Half the Cost
Enterprise Cloud Computing

On Force.com
Network Security
Unlock The Potential In Your People
Average Rating:
Rate this article:  
Microsoft Patch Tuesday Brings Critical Fixes, Also for Surface
Microsoft Patch Tuesday Brings Critical Fixes, Also for Surface

By Jennifer LeClaire
November 9, 2012 9:19AM

    Bookmark and Share
With another Microsoft Patch Tuesday on the way, we asked security and forensic analyst Paul Henry what IT admins and Windows users need to know. Expect a disruptive Patch Tuesday. "With 6 Microsoft bulletins, 4 of which are critical and some restarts required, along with a host of other issues, IT can expect a disruptive Patch Tuesday this month."
 



(Page 2 of 2)

"If these fonts are embedded in a browser or a Word document, for example, it's rendered in the kernel mode driver and winds up becoming a kernel mode exploit. An authenticated, low-rights user could visit a Web site, the font gets rendered, and it gets rendered as 'system.' This is a very effective attack mode, so Microsoft likes to close out font issues quickly. This is as high a priority as Bulletin 1. Those two bulletins will be the two biggest attack vectors in this batch."

Bulletin 2 addresses two vulnerabilities that are critical remote code executions. This is a Briefcase issue, where you have mapped drives with Briefcase, and Henry classifies it as high priority. Meanwhile, Bulletin 4 affects .Net and fixes Bulletin 5 vulnerabilities in the .Net framework. Bulletin 6 is an Excel vulnerability.

"Bulletin 3 is a moderate update for IIS, which could cause concern. But this is an information disclosure issue via FTP only, so it's only a concern if you have IIS set up to provide FTP services," Henry said. "It's moderate, which typically means attackers have to authenticate to pull off the attack. And we all recognize if they can authenticate, they pretty much own the machine anyway."

< Previous Page  |  1  |  2

 

Tell Us What You Think
Comment:

Name:

Product Information and Resources for Technology You Can Use To Boost Your Business

Enterprise Hardware Spotlight
Dell Kills Its Public Cloud Effort, Will Offer Partner Marketplace
Putting the kibosh on its efforts to build out a public cloud, Dell has announced a new program to offer a choice of cloud Infrastructure-as-a-Service through a central marketplace of partners.
 
Dell's Dismal Quarter Shows PC Maker's Challenges
Dell's financial decay worsened during its latest quarter as the company slashed its personal computer prices in response to the growing popularity of smartphones and tablets in the beleaguered industry.
 
U.S. Defense Department Gives iOS 6 Security OK
In a vote of confidence for Apple's iOS devices, the Defense Department has given the all-clear for employees to use iPads and iPhones for work. But only those running iOS 6, and only if issued by the government.
 

Mobile Enterprise Spotlight
Viva Movil! Buy a Phone from J.Lo
Latina pop sensation and entrepreneur Jennifer Lopez is teaming with Verizon Wireless on a new 4G LTE network and wireless service dubbed Viva Movil by Jennifer Lopez, aimed at the U.S. Latino market.
 
Samsung Sells 10 Million Galaxy S IVs -- Four Every Second
The new Galaxy S IV smartphone from Samsung is off to a strong start. The South Korean manufacturer has announced that global sales for the device have exceeded 10 million units in one month.
 
Google Adds Conversational Search to Chrome
If you like chatting with Siri, sending voice texts while driving or telling your Xbox when to pause or rewind a DVD, you're going to enjoy the upgrade to Google's Chrome browser.
 

Enterprise Technology Spotlight
New Nvidia Chip Boosts Citrix Graphics for Remote Workers
The latest Nvidia Graphics Processing Unit (GPU) promises to boost remote graphics sharing through the Citrix remote desktop service. The new chip delivers better graphics for remote workers.
 
Security Alert: Beware of Tiffany Trojan on the Attack
Malware writers are using a luxury name to hack your PC. Security watchdog Sophos reports e-mails appearing to be from Tiffany.com carry an attachment that can install a malicious Trojan on your PC.
 
Blue Coat Beefs Up Big Data Security with Solera Buy
California-based Blue Coat Systems is expanding into Big Data security in the advanced threat protection space. The company has snapped up Intel-backed Solera Networks for its DeepSee platform.
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Cloud & Virtualization | Applications | Unified Communications | Mobile Tech | Hardware | Business Intelligence
World Wide Web | Network Security | Data Storage | Small Business | Microsoft/Windows | Apple/Mac | Linux/Open Source | Personal Tech
Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2013 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.