Newsletters
News & Information for Technology Purchasers NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
This ad will display for the next 20 seconds. Please click for more information:
Home Enterprise I.T. Cloud & Virtualization Applications Unified Communications More Topics...
Commvault Simpana® 10
Protect, manage, access, and
realize the untapped value of data.

www.commvault.com
Network Security
Unlock The Potential In Your People
Average Rating:
Rate this article:  
Microsoft Patch Tuesday Brings Critical Fixes, Also for Surface
Microsoft Patch Tuesday Brings Critical Fixes, Also for Surface

By Jennifer LeClaire
November 9, 2012 9:19AM

    Bookmark and Share
With another Microsoft Patch Tuesday on the way, we asked security and forensic analyst Paul Henry what IT admins and Windows users need to know. Expect a disruptive Patch Tuesday. "With 6 Microsoft bulletins, 4 of which are critical and some restarts required, along with a host of other issues, IT can expect a disruptive Patch Tuesday this month."
 




(Page 2 of 2)

"If these fonts are embedded in a browser or a Word document, for example, it's rendered in the kernel mode driver and winds up becoming a kernel mode exploit. An authenticated, low-rights user could visit a Web site, the font gets rendered, and it gets rendered as 'system.' This is a very effective attack mode, so Microsoft likes to close out font issues quickly. This is as high a priority as Bulletin 1. Those two bulletins will be the two biggest attack vectors in this batch."

Bulletin 2 addresses two vulnerabilities that are critical remote code executions. This is a Briefcase issue, where you have mapped drives with Briefcase, and Henry classifies it as high priority. Meanwhile, Bulletin 4 affects .Net and fixes Bulletin 5 vulnerabilities in the .Net framework. Bulletin 6 is an Excel vulnerability.

"Bulletin 3 is a moderate update for IIS, which could cause concern. But this is an information disclosure issue via FTP only, so it's only a concern if you have IIS set up to provide FTP services," Henry said. "It's moderate, which typically means attackers have to authenticate to pull off the attack. And we all recognize if they can authenticate, they pretty much own the machine anyway."

< Previous Page  |  1  |  2

 

Tell Us What You Think
Comment:

Name:

>

Product Information and Resources for Technology You Can Use To Boost Your Business

Enterprise Hardware Spotlight
Cisco Surges After Profit Exceeds Analysts' Estimates
Networking equipment giant Cisco's net income jumped 14 percent in the latest quarter as revenue at all four of its divisions rose for the first time in a year and a half, as tech spending increases.
 
HP and SAP Team To Advance HANA Database Technology
The two tech leaders are working on a system that SAP says could fundamentally change the database market. HANA is SAP's technology that keeps data in-memory, for super fast processing.
 
Square Stand Turns iPad into Digital Cash Register
Mobile-payments start-up Square has designs on reinventing the cash register with the Square Stand, which transforms an iPad tablet into a digital point-of-sale system to replace cash registers.
 

Mobile Enterprise Spotlight
Google Glass Raises Congressional Privacy Concerns
The buzz around Google Glass continues, but it's not all good. Some in Congress have questions. "We are curious whether this new technology could infringe on the privacy of average Americans," their letter to Google says.
 
Windows Phone Now No. 3 in Market, BlackBerry No. 4
Has Microsoft Phone moved into a coveted though distant third place for smartphone platforms behind Google's Android and Apple's iOS? A new report says yes, while BlackBerry has slipped to No. 4.
 
Intel Going Mobile with Its New CEO
In his first speech as Intel's CEO, Brian Krzanich said he plans to focus on beefing up Intel's presence in mobility. The next step: a world tour showing mobile devices based on Intel chips, from PCs to phones and tablets.
 

Enterprise Technology Spotlight
HP and SAP Team To Advance HANA Database Technology
The two tech leaders are working on a system that SAP says could fundamentally change the database market. HANA is SAP's technology that keeps data in-memory, for super fast processing.
 
Cloud Computing Gains Another Competitor with Google
Amazon Web Services and Microsoft Azure now have a full-on rival in Google, with its I/O announcement that it is opening its hosted Compute Engine environment for virtual machines to all comers.
 
Hackers' New Tool of Choice: Smartphones
Smartphones are increasingly popular not only with consumers, but with thieves who see the devices as another way to tap into bank accounts and other sensitive information, experts say.
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Cloud & Virtualization | Applications | Unified Communications | Mobile Tech | Hardware | Business Intelligence
World Wide Web | Network Security | Data Storage | Small Business | Microsoft/Windows | Apple/Mac | Linux/Open Source | Personal Tech
Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2013 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.