Welcome | Sign In
CRMBuyer.com
Exploits & Vulnerabilities

Microsoft Preps for Ginormous Patch Tuesday

Print Version
E-Mail Article
Reprints
Microsoft Preps for Ginormous Patch Tuesday

The Microsoft Patch Tuesday update set to drop on Oct. 13 will be a record-breaker at 13 bulletins. Redmond rated eight of the 13 as critical, the rest as important. The flaws behind two of the bulletins -- one for Server Message Block 2.0, the other for Internet Information Services -- were discovered about a month ago.


Considering CRM solutions?
You first need to understand CRM best practices. Before committing to a CRM purchase and implementation, it's good to know the experience of those who have already "been there, done that." It can save time and prevent costly missteps. Download Free Research.

Microsoft (Nasdaq: MSFT) on Friday announced that it will issue a record 13 security bulletins on its next scheduled Patch Tuesday, which will arrive Oct. 13.

It rates eight of these as critical and the rest as important.

The bulletins address 34 vulnerabilities across a variety of Microsoft products, ranging from Windows to its Forefront security app to Internet Explorer.

What's the Buzz?

Ten of the 13 bulletins address flaws that enable remote code execution. Eight of these are ranked critical and the other two important.

Of the remaining bulletins tagged important, one targets a problem that enables spoofing; one elevation of privilege; and the last denial of service.

Systems administrators should install all the patches regardless of whether they are tagged critical or not, warned Randy Abrams, director of technical education at security vendor ESET.

"It's an error to think you have any significantly higher degree of protection if you don't patch all known vulnerabilities," he told TechNewsWorld. "They will probably all be included in exploit packages, and just one unpatched vulnerability becomes as bad as leaving them all unpatched."

Microsoft will host a webcast to address customer Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse questions about these bulletins on Oct. 14 at 11 a.m. Pacific time. The webcast will be available on demand after that.

What's Affected

Vulnerabilities in 12 of the bulletins impact the Windows operating system.

The other Microsoft software products to which the Patch Tuesday bulletins will apply are Office, Silverlight, SQL Server, Developer Tools and Forefront.

Forefront is Redmond's attempt to deliver end-to-end security and manage access to information through an integrated line of protection, access and identity management products.

The problems behind two of the 13 bulletins, which take aim at vulnerabilities in Server Message Block Version 2.0 (SMBv2) and the file transfer protocol (FTP) service in Internet Information Services (IIS), were first discovered a month ago.

SMB is the file-sharing protocol used by default on computers running Microsoft Windows. Version 2.0 runs only on Windows Server 2008 and Windows Vista. The vulnerability in SMBv2 is caused when the SMB implementation does not appropriately parse SMBv2 negotiation requests.

An attacker who successfully exploits this vulnerability can take complete control of the victim's system. This vulnerability affects all versions of Windows Vista and Windows Server 2008. It also impacts Windows 7 Release Candidate. Microsoft issued Security Advisory 975497 in September as a stopgap measure to deal with this vulnerability.

The FTP service flaw occurs in IIS 5.0 through 7.0 running on various versions of Windows 2000, XP, Windows Server 2003, Vista and Windows Server 2008.

It could allow remote code execution or denial of service (DoS) on systems running FTP Service on IIS 5.0. The flaw allows DoS on the other versions of IIS through 7.0.

Microsoft issued Security Advisory 975191 for this vulnerability in September.

Users may have put the squeeze on Microsoft to resolve these two flaws, Michael Sutton, VP of Security Research at cloud security provider Zscaler, told TechNewsWorld. "It's not common for Microsoft to comment on the specific issues that will be addressed during a patch cycle, so one can assume that they've been under pressure to address these items as quickly as possible," he explained.

"It's encouraging to see that these issues will be addressed on Tuesday as they represent a very real threat."

Phrying up Some Phish

Microsoft acknowledged that the number of bulletins is a new record. "Prior to this release, the most bulletins Microsoft has ever released in a month is 12," company spokesperson Robert Kremers told TechNewsWorld. However, he declined to discuss the bulletins in detail.

Is the record number of bulletins linked to the FBI's well-publicized "Operation Phish Phry" in which 100 people were arrested in the United States and Egypt on Wednesday in connection with a phishing ring?

Not necessarily, ESET's Abrams said. "Microsoft may have been sitting on some vulnerabilities that had not been known to be exploited while they completed a thorough test cycle," he explained. "There is also a lot more focus by the bad guys investing in finding vulnerabilities."

Most phishing and spam attacks involve either social engineering or target previously published vulnerabilities that have been left unpatched, according to Zscaler's Sutton. "Microsoft has made significant strides improving the security of their products," he said. "While they still face challenges with client-side vulnerabilities, critical server-side vulnerabilities have diminished in recent years."

Security vendors have their work cut out for them, ESET's Abrams said. "We are making some progress, but when you start tearing down a mountain, 2,000 truck loads of dirt do not make a visible difference," he added. "There is most of a mountain of ignorance left to educate."


Print Version E-Mail Article Reprints More by Richard Adhikari


Related News Alerts

Microsoft Activate Alert | Search Archives

More by Richard Adhikari

New Pogoplug Brings Mobile Devices Into the Cloud
November 20, 2009
The Pogoplug allows a user to run a personal cloud server from a home network. The data resides on hard drives and thumb drives that plug directly into the Pogoplug device; from there, the data can be accessed from anywhere via the Internet. Keep in mind that some ISPs forbid customers from hooking servers up to residential connections, though those rules are rarely enforced.
Google Spills Chrome OS' Guts
November 19, 2009
Google has made public the source code for its upcoming Chrome operating system. The OS will begin appearing on consumer-targeted netbooks next year. Chrome is built to live completely on the Web -- very little data is stored directly on the user's hard drive. This could make for much faster boot times and enhance security.
Cyberfraud Arrests Unlikely to Stem ZeuS Rampage
November 18, 2009
Two alleged cybercrooks have been nabbed in the UK on suspicion of using a well-know Trojan to commit banking fraud. The malware in question in known as "ZeuS" or "Zbot," and althought it's quite common, it's also sometimes difficult for antivirus applications to nail. Simple software kits exist online for relatively inexperienced hackers to create unique malware for the purpose of fraud.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network