Newsletters
News & Information for Technology Purchasers NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
Home Enterprise I.T. Cloud & Virtualization Applications Unified Communications More Topics...
Brocade delivers
cloud-optimized networking solutions
to deploy, manage, and scale networks.

www.brocade.com
Network Security
Get paper data into SharePoint!
Average Rating:
Rate this article:  
Analysts: Patch Microsoft IE Drive-By Vulnerability First
Analysts: Patch Microsoft IE Drive-By Vulnerability First

By Jennifer LeClaire
November 14, 2012 10:00AM

    Bookmark and Share
Despite the release of Windows 8 in late October, security researcher Andrew Storms noted that three of Tuesday's bulletins already affect it. Much of the core operating system is reused from version to version, even in new releases, and all software has bugs, he explained. Six security fixes total were issued as part of Microsoft's monthly Patch Tuesday.
 



Microsoft Relevant Products/Services on Tuesday released six bulletins as part of its monthly patch process. The patches fix flaws in Windows, Office and .NET Framework.

Microsoft recommends IT admins apply all of the security updates as soon as possible. Redmond prioritized MS12-071, which addresses vulnerabilities in Internet Explorer, and MS12-075, which fixes issues in Windows Kernal-Mode Driver.

"We are committed to improving the security of all our products," said Dave Forstrom, director of Trustworthy Computing at Microsoft. "When security updates are released, customers who have Automatic Updates enabled will be protected automatically and do not need to take an action."

First Things First

We turned to Andrew Storms, director of security operations at nCircle, to get his take on November's Patch Tuesday. He agreed that the priority is the drive-by exploit affecting Internet Explorer 9.

"It's fairly obvious that Microsoft patched this bug in IE10 before its release. Otherwise, we would have a bulletin affecting both IE9 and IE10," Storms told us.

The second bug on his list is MS12-075. One of the bugs in this bulletin affects TrueType fonts and creates a theoretical exploit vector with third-party browsers. Storms recommended patching this one immediately after the IE9 bug.

"The .NET bug that looked problematic in last week's advanced notification is not as serious as it could have been. The remote Relevant Products/Services exploit of this bug is complex; it's going to be difficult for most attackers to use," Storms said. "This is the kind of bug that is a popular tool for pen testers with local network Relevant Products/Services access to show off possible attack vectors, so you should definitely patch it sooner rather than later."

IT Lockdown

Despite the release of Windows 8 in late October, Storms noted that three of Tuesday's bulletins already affect it. Much of the core operating system is reused from version to version, even in new releases, and all software Relevant Products/Services has bugs, he explained. These factors, combined with security researchers that love to find and report bugs in the latest software version, he said, are reasons for the number of bulletins for Windows 8. This should surprise no one.

"Many financial and retail organizations go into IT 'lock-down' for the last few months of the year. They don't want to introduce any changes that may impact their ability to process transactions during the holiday shopping season," Storms said. "It's likely that none of today's patches will be applied to the server Relevant Products/Services infrastructure Relevant Products/Services of these organizations, so Microsoft's comprehensive mitigation advice is critical. It allows these organizations to mitigate the security risk without compromising downtime."

Tyler Reguly, technical manager of security research and development at nCircle, said there's really nothing to talk about with regard to Windows 8 and Server 2012. As he sees it, if you're looking for an operating system without vulnerabilities, you might as well check the end of the rainbow for a pot of gold or try to catch a unicorn.

"Microsoft's recent actions with Flash in IE10 surprised me. I've always felt Security Advisories were the geekier communication mechanism and Security Bulletins were meant for a wider audience," Reguly said. "Yet, they've made the decision to go with Security Advisories only for Flash updates, a divergence from the approach they took when XP shipped with Flash built-in."
 

Tell Us What You Think
Comment:

Name:



Brocade delivers a comprehensive cloud-optimized networking portfolio of products and open-architecture solutions to simplify and accelerate the deployment of cloud computing and provide maximum deployment flexibility with plug-in scalability. Click here to learn more.


 Network Security
1.   Snowden To Dish More Info on NSA
2.   Prism's Secret: Bigger Data Seizure
3.   Keeping Your Data Safe from Spying
4.   Google Uses Secure FTP for NSA
5.   Google Reports Iran Phishing Attacks


advertisement
Bank Phishing Attacks Raise Fears
Business, personal accounts at risk.
Average Rating:
Snowden To Dish More Info on NSA
On access to tech companies' servers.
Average Rating:
Prism's Secret: Bigger Data Seizure
Two vital components to its success.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Enterprise Hardware Spotlight
Samsung Offers Tiny, Superfast PCIe SSDs for Ultrabooks
Solid-state drives are continuing their march forward. On Monday, Samsung Electronics announced it has started to mass produce the first PCI-Express 3.0 SSDs for the new wave of Ultrabooks.
 
Amazon.com Joins 3D Printer Craze, Enabling Wide Availability
Commercially available 3D printers have recently moved from being expensive hobbyist devices to being pricey but accessible consumer and manufacturing machines. And now, Amazon.com will sell 3D printers & supplies online.
 
New Facebook Data Center Uses All Home-Grown Servers
Facebook has opened its new data center in Lulea, Sweden. The data center is a first in two ways: the first in Europe and the first to be equipped with all Facebook-designed, Open Compute servers.
 

Enterprise Technology Spotlight
Texting Spammers Correlate Phone Users to Local Banks
If you use an Internet-connected smartphone, touch tablet, e-reader, notebook, laptop or desktop computer you care about cybersecurity and online privacy. One topic: SMS text-messaging spam.
 
New Facebook Data Center Uses All Home-Grown Servers
Facebook has opened its new data center in Lulea, Sweden. The data center is a first in two ways: the first in Europe and the first to be equipped with all Facebook-designed, Open Compute servers.
 
Cisco Telecom Router Ready for Internet Traffic Flood
The Carrier Routing System-X unveiled by Cisco for the telecommunications industry is a 400 Gbps per slot system that can be expanded to nearly 1 petabit per second, enough to deal with the coming flood in demand.
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Cloud & Virtualization | Applications | Unified Communications | Mobile Tech | Hardware | Business Intelligence
World Wide Web | Network Security | Data Storage | Small Business | Microsoft/Windows | Apple/Mac | Linux/Open Source | Personal Tech
Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2013 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.