Data Storage Today

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
News & Information for Data Storage Professionals
Friday, September 3rd 
Home
Storage Hardware
Storage Software
Storage Networks
Storage Trends
Next-Gen Storage
Data Security
DST Press Releases
 
Free Newsletters
Top CIO News
 
Mobile Tech Today
 

Advertisement
Data Security

IE Vulnerability Heads Microsoft's Patch Tuesday List

IE Vulnerability Heads Microsoft
December 4, 2009 8:08AM

Bookmark and Share
Patch Tuesday will address a vulnerability in Internet Explorer severe enough that Microsoft considered an out-of-band patch. Microsoft's Patch Tuesday also addresses a Windows Server 2008 flaw that could be disruptive and a Project 2000 problem. A recently announced TLS flaw in browsers and servers is apparently not patched.


The coming week will be a busy one for IT Relevant Products/Services administrators. Microsoft plans to release six patches for December's Patch Tuesday -- three rated critical and three important. The patches will address 12 vulnerabilities in Windows, Internet Explorer, and Microsoft Office.

"To help customers plan for their deployment of these updates, I want to specifically call out that they touch all supported versions of Windows and IE," said Jerry Bryant of the Microsoft Security Response Center. "On the Office side, the bulletins impact Project, Word and Works 8.5. All of the updates for Windows will require a restart, so please plan accordingly."

Patching the IE Flaw

At the top of the list for IT administrators -- and at the top of Microsoft's deployment list -- is a vulnerability in IE 6 and 7 that could lead to remote code execution. Although Microsoft is not aware of any active attacks that seek to exploit this vulnerability, it is severe enough that the company considered releasing an out-of-band patch on Nov. 23.

The IE fix is part of Bulletin 4, which will have the broadest impact because it will affect all user machines across an entire organization, according to Don Leatham, Lumension senior director of solutions and strategy.

"It is critical across Windows 7, Vista and XP; requires a restart; and impacts all versions of Internet Explorer 6, 7 and 8," Leatham said. "We suggest that IT departments be prepared to quickly assess and patch all end-user machines throughout their organization."

Disrupting Windows Server

Bryant said the other critical update affecting Windows is in Bulletin 1. Although this bulletin has a critical severity rating, he said, the lower risk will drop the deployment priority down a little. But security researchers said the importance shouldn't be underestimated for Windows Server 2008 users.

"If IT teams have Windows Server 2008 deployed in support of mission-critical applications, this update could be disruptive," Leatham said. "If the associated vulnerabilities are rated high on Microsoft's exploitability scale, organizations may be forced to pull production servers out of service for patching."

Bulletin 3 is critical for Project 2000. Since the majority of people use later versions of Microsoft Project, Leatham said, any attack associated with this update should be fairly narrow. Nonetheless, he added, IT teams should ensure that they have identified all instances of Project 2000 that may still exist in their organization.

What about the TLS Flaw?

Leatham said it appears that Microsoft isn't issuing a patch for the recently announced TLS flaw that will most likely force updates to all brands of browsers and all Internet servers using SSL/TLS. The flaw allows attackers to inject text into encrypted traffic.

"Although we'll have to wait until Patch Tuesday for confirmation, we are led to believe that Microsoft has chosen not to address this vulnerability in this round of patches," Leatham said. "There is controversy in the security community as to the true importance of speeding a fix to market for this flaw, and no widespread exploits have been reported."

Tell Us What You Think
Comment:

Name:

Advertisement



 Data Security
1. VMware Reinforces 'IT as a Service'
2. Hackers Invade iTunes Accounts
3. Security Threats a Record, IBM Says
4. Germany To Halt Facebook Checks
5. Private Modes Have Security Holes


advertisement


 Most Popular Articles
1. Dell Buys Virtualization Storage Provider 3PAR
2. Patch Fixes SMB Attack That Could Come from Within
3. Intel Will Acquire McAfee To Secure Online Computing
4. Apple Issues iOS Patch To Block Hacker Bonanza
5. Microsoft's August Patches Will Keep IT Admins Busy

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  HP Wins 3PAR at $2.4B as Dell Quits
  Data Storage Advances Are Looming
  VMware Reinforces 'IT as a Service'
  Dell Ponders Matching HP 3PAR Bid
  Why Does Everyone Want 3Par?

 Technology Marketplace
Compliance
Stand out from other IS Professionals and increase your earning potential.®.
Manage limitless content today—read EMC’s 15-minute guide to ECM.
 
Data Storage
Isilon scale-out storage is simple. Simple is smart.
 
Digital Life
IT PROS: Receive $10 in rewards to complete a 15 min. survey.
 
Enterprise I.T.
Stand out from other IS Professionals and increase your earning potential.®.
IT PROS: Receive $10 in rewards to complete a 15 min survey.
 
Enterprise Software
Manage limitless content today—read EMC’s 15-minute guide to ECM.
 
Mobile Gadgets
White Paper The Motorola ES400: Desktop power in a pocket-sized device
 
Mobile Industry News
The Motorola ES400: Desktop power in a pocket-sized device.
 
Mobile Phones
The Motorola ES400: Desktop power in a pocket-sized device.
 
Navigation
Data Storage Today
Home/Top News | Storage Hardware | Storage Software | Storage Networks | Storage Trends | Next-Gen Storage | Data Security
DST Press Releases
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 Data Storage Today. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.