Data Storage Today

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
News & Information for Data Storage Professionals
Thursday, September 9th 
Home
Storage Hardware
Storage Software
Storage Networks
Storage Trends
Next-Gen Storage
Data Security
DST Press Releases
 
Free Newsletters
Top CIO News
 
Mobile Tech Today
 

Advertisement
Data Security

Microsoft Patches New and Old Software Flaws

Microsoft Patches New and Old Software Flaws
October 14, 2009 9:34AM

Bookmark and Share
Microsoft's Patch Tuesday release includes new and old software vulnerabilities, and those marked critical allow remote code execution. That means computer restarts and a heavy workload for IT administrators. Analysts pointed to some Microsoft patches that are particularly important in Tuesday's release of security bulletins.


Microsoft released its largest-ever batch of security updates Tuesday, fixing 33 vulnerabilities in Windows, Internet Explorer, and other popular software. Eight of the updates are rated critical and five are rated important.

All the critical vulnerabilities are labeled as remote code execution, which would require system restarts and impact a very broad range of Windows platforms and applications, according to Lumension security and forensic analyst Paul Henry. But, he noted, IT Relevant Products/Services administrators should pay attention to two particular security bulletins, as their vulnerabilities are being exploited in the wild: MS09-050 and MS09-053.

MS09-050 is a critical vulnerability that impacts both Vista and Windows 2008 platforms. While only rated as important, Henry said, MS09-053 should be considered a priority for organizations running public-facing FTP servers. He said organizations that use the Internet daily should also pay close attention to the high-priority critical client-side issues that could allow drive-by hacking exploits.

"Because of the large number of issues covered in this month's patch release, it is important that organizations carefully review the bulletin in its entirety and then carefully plan their patch-management Relevant Products/Services priorities and process based on the impact on their given product utilization and the likelihood of exploitation," Henry said. "Simply put, the administrative burden of flaw remediation today is clearly beyond that which can be handled without full flaw-remediation process automation."

Cleaning Up Old Messes

Andrew Storms, director of security operations for nCircle, has a different take. As he sees it, the bug that is likely to have the biggest impact on Microsoft users will be MS09-051, the speech-codec bug that already has limited exploits in the wild. This is a typical file-parsing issue and similar vulnerabilities have allowed attackers to create drive-by attacks that infect unsuspecting video viewers.

"MS09-056 isn't a critical vulnerability and it doesn't rate high on the exploitability index, but it does offer some insight into Microsoft security processes," Storms said. "Microsoft couldn't fix all the problems with nefarious Web SSL certifications, so they apparently reached out to all trusted root-certificate authorities to make sure they have a process that disallows signatures of null-byte certificates."

The SMB and IIS bugs, both acknowledged by Microsoft in early September, have received quite a bit of attention in the past month. The SMB vulnerability is difficult to exploit given default firewall conditions, Storms noted, but the IIS bugs are easy to exploit. The risk for these vulnerabilities didn't warrant an out-of-band patch, he said, but are included in this month's whopper of a release.

Firefox Users At Risk

As a researcher who provides product content Relevant Products/Services, Tuesday's release made Tyler Reguly, a senior security engineer at nCircle, very uncomfortable. The sheer size of the release and the tangle of vulnerabilities, he said, made it a long night for researchers everywhere looking for useful information Relevant Products/Services for their customers.

"Again we see a month of client-side issues in almost every major Microsoft product. Whether you run Office, Windows Media Player, IE, .NET or just Windows itself, there's a vulnerability for you," Reguly said.

"Those with a Web-based attack vector are always important. Also this month, keep in mind that even Firefox users aren't safe from the IE vulnerability. There is a Firefox attack vector available, so patching IE should be considered crucial even if you never open it."

Tell Us What You Think
Comment:

Name:

Advertisement



 Data Security
1. Symantec Unwraps Norton 2011 Suite
2. Spammers Take Over Apple's Ping
3. VMware Reinforces 'IT as a Service'
4. Hackers Invade iTunes Accounts
5. Security Threats a Record, IBM Says


advertisement


 Most Popular Articles
1. Dell Buys Virtualization Storage Provider 3PAR
2. Patch Fixes SMB Attack That Could Come from Within
3. Intel Will Acquire McAfee To Secure Online Computing
4. Apple Issues iOS Patch To Block Hacker Bonanza
5. Intel's Deal for 'Buggy Whip' Maker McAfee Will Impact IT

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  Symantec Unwraps Norton 2011 Suite
  Dell's Data Center Ambitions Remain
  Create a PC Toolkit in Your Pocket
  HP vs. Dell: Behind the Showdown
  Spammers Take Over Apple's Ping

 Technology Marketplace
Chips & Processors
Is your organization overdue for a desktop or laptop refresh?
Upgrade your computers with HP and Intel
 
Compliance
Manage limitless content today—read EMC’s 15-minute guide to ECM.
 
Data Storage
Isilon scale-out storage is simple. Simple is smart.
 
Digital Life
IT PROS: Receive $10 in rewards to complete a 15 min. survey.
 
Enterprise Hardware
Is your organization overdue for a desktop or laptop refresh?
Upgrade your computers with HP and Intel
 
Enterprise I.T.
IT PROS: Receive $10 in rewards to complete a 15 min survey.
 
Enterprise Software
Manage limitless content today—read EMC’s 15-minute guide to ECM.
 
Mobile Gadgets
White Paper The Motorola ES400: Desktop power in a pocket-sized device
 
Mobile Industry News
The Motorola ES400: Desktop power in a pocket-sized device.
 
Mobile Phones
The Motorola ES400: Desktop power in a pocket-sized device.
 
Navigation
Data Storage Today
Home/Top News | Storage Hardware | Storage Software | Storage Networks | Storage Trends | Next-Gen Storage | Data Security
DST Press Releases
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 Data Storage Today. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.