Microsoft plans to issue seven sets of security patches next week for Windows.
Bluetooth, IE to Get Critical Microsoft Patches
Microsoft plans to issue seven sets of security patches next week, including critical fixes for DirectX, Internet Explorer and Bluetooth wireless software for Windows.
The updates are due Tuesday, the day Microsoft had previously scheduled to release its security patches. Fixes are also slated for Active Directory, the Windows Internet Name Service (WINS) and the Pragmatic General Multicast (PGM) protocol, used by Windows to stream media to many recipients. These updates are all rated "important."
A seventh update, rated "moderate," is listed as a "Kill Bit" update for Windows. This type of patch will disable code that is known to have a security bug.
"The Kill Bit will more than likely be for a third-party application," said Andrew Storms, director of security operations with security vendor nCircle.
Lately, Microsoft's security group has had to pay more attention to software that runs on top of Windows, as attackers have increasingly looked to products like QuickTime, Adobe's Flash and other media players when devising their attacks.
Last Friday, Microsoft warned that a widely publicized flaw in Apple's Safari browser could be combined with another Microsoft bug to let attackers run unauthorized software on a victim's PC.
It's not clear whether Microsoft plans to patch that bug. The IE update could include a fix, although it's unlikely that Microsoft has had enough time to run this software through its testing process, Storms said.
It is unusual for Microsoft to patch Bluetooth, a protocol used to connect devices like headsets to Windows, but added that "the more interesting question is will this patch and/or the bug extend into Windows mobile where it will more than likely have a greater impact?"
Microsoft announced the planned patches in a note posted to its Web site on Thursday.
Friday, June 6, 2008
Bluetooth, IE to Get Critical Microsoft Patches
Posted by
Ran Werkheiser
at
19:56
0
comments
Labels: microsoft, online security, patch, update, windows xp
Wednesday, February 13, 2008
Microsoft Releases Patches
Eleven security updates are released today that fix a number of critical flaws in Microsoft products, including Windows, Office, and Internet Explorer.
Microsoft Releases Massive Set of Security Updates
Robert McMillan, IDG News Service
Microsoft released 11 security updates today that fix critical flaws in its products, including a publicly known ActiveX bug that affects users of the Visual FoxPro database.
In total, 17 individual software flaws were patched in the updates. Microsoft rates six updates as critical, meaning they should be installed as soon as possible, while the remaining five updates are considered "important." Last month was an easier month on IT administrators, when Microsoft released just two updates.
Microsoft surprised some by releasing one less update than expected. Last Thursday the software vendor had said that it was readying a fix for critical VBScript and JScript flaws in Windows 2000, XP, and Windows Server 2003. That update wasn't included in this week's patches, but Microsoft today wouldn't confirm that it had actually dropped the update because "this could put customers at risk," according a spokeswoman for the company's public relations agency.
Security experts said Tuesday that the MS08-010 update, which fixes four bugs in Internet Explorer, should take top priority this week. "There are four vulnerabilities within that particular patch and all of them are remote-code executable," said Jonathan Bitle, director of technical account management with Qualys.
"The way we're looking at it, our prioritization would put MS08-010 at the top followed by MS08-007," said Don Leatham, director of solutions and strategy with Lumension Security.
MS08-010 fixes a publicly disclosed ActiveX bug that affects Visual FoxPro users. Although hackers have already posted code showing how to exploit this vulnerability, the buggy ActiveX control is not included in Internet Explorer 7's default list of controls, so the flaw should not affect most users.
The MS08-007 update fixes a critical flaw in the Windows XP and Vista WebDAV redirector software. WebDAV is a Web-based document sharing protocol. The flaw is rated important for Windows Server 2003 users.
Microsoft's Office products are also a major source of patches this month.
Tuesday's updates include critical fixes for Microsoft Word, Office Publisher and in Office itself.
There is also a critical update for Windows' Object Linking and Embedding (OLE) Automation software.
The remaining updates, rated important, are for Active Directory, the Vista TCP/IP stack, the Microsoft Works file converter and two bugs in the Internet Information Services (IIS) Web server.
The Patch Tuesday updates show that client-side bugs continue to be a much higher risk than server-side vulnerabilities, said Andrew Storms, director of security operations with nCircle. "One would have assumed that the IIS and Active Directory vulnerabilities would have been the most serious because they stand at the core of an enterprise and provide more critical services" he said via instant message. "But with this month's patches, the hacker's best bet is to take advantage of the client-side attacks."
source: PCWorld
Posted by
Ran Werkheiser
at
09:12
0
comments
Wednesday, January 9, 2008
Microsoft's First Roundup of Patches
The first set of patches for 2008 was released by Microsoft this Tuesday, fixing a pair of networking flaws in the Windows kernel.
Microsoft Releases a New Set of Patches
Microsoft has released a patch to fix a security flaw in Windows that could be used by criminals to create as self-copying computer worm attack. The patch fixed a pair of networking flaws in the Windows Kernel. Another patch was also released for a less-serious Windows flaw that would allow attackers to steal passwords or run Windows software with elevated privileges.
The critical bug lies in the way Windows processes networking traffic that uses IGMP (Internet Group Management Protocol) and MLD (Multicast Listener Discovery) protocols, which are used to send data to many systems at the same time. Microsoft says that an attacker could send specially crafted packets to a victim's machine, which could then allow the attacker to run unauthorized code on a system.
No known code exploits this flaw, security experts say, but now that the patch has been posted, hackers can reverse-engineer the fix and create their own attack code. Since IGMP is enabled both in Windows XP and Vista by default, the bug could be used to create a self-copying worm attack, Microsoft has disclosed.
"Theoretically this is wormable and that's why this is rated critical," said Tim Rains, security response communications lead with Microsoft. However, Microsoft does not believe that hackers will have an easy time developing attack code that will work reliably. "We've done a thorough analysis of the vulnerability and we've come to the conclusion that there are several technical mitigating factors that make it unlikely to get reliable remote code execution," Rains said.
Windows uses the IGMP protocol for many popular consumer applications such as streaming video, multiplayer games and universal plug-and-play, but the protocol is usually blocked at the router. A derivative of IGMP, MLD is the multicast protocol used by IPv6 systems and is enabled on Vista by default
"If it became a worm it could take over an internal network pretty quickly, or at least all the machines where multicast is enabled," said Eric Schultze, chief technology officer with Shavlik Technologies. "But this one is going to be mitigated because a lot of people have blocked multicast."
Posted by
Ran Werkheiser
at
18:39
0
comments
Labels: bug, patch, windows vista, windows xp, worm
Tuesday, December 25, 2007
IE Still has Problems
After users reported problems with the recent patch of Internet Explorer, Microsoft offered a way to work around the unexpected bug.
Microsoft Offers Work-Around IE's Problem
Microsoft released a critical security patch for Internet Explorer last Tuesday, fixing some bugs in the browser. However, soon after users installed it, they began reporting that Internet Explorer would crash when visiting certain websites. Windows would then report that 'Internet Explorer has encountered a problem and needs to close'
Microsoft has offered a technical work-around for Internet Explorer users who have found their browsers crashing after installing a recent set of security patches. Microsoft now says that the problem is not widespread and affects certain custom installations of Internet Explorer 6 on Windows XP, Service Pack 2.
Users who have experienced this problem can fix it by making some tweaks in the Windows Registry, described in this Knowledge Base article.
Microsoft did not say what kind of customization would cause the bug, and company representatives were not immediately available for comment.
Some newsgroup users are speculating, however, that the issue may be related to antivirus software. Symantec and McAfee users who have been experiencing the problem have been able to resolve the issue by uninstalling the security update and then uninstalling their antivirus software, installing the update and then reinstalling their AV products, said Frank Saunders, a Windows user who has been following discussion of the issue.
The Internet Explorer patch associated with this problem -- MS07-069 -- is considered to be the most important of last week's updates because it fixes four critical vulnerabilities in the browser.
Posted by
Ran Werkheiser
at
07:31
0
comments
Labels: internet explorer, microsoft, patch
Friday, December 14, 2007
QuickTime Bug Squashed
Apple releases a patch to update a critical flaw, making it the eight update this year for QuickTime.
Apple Fixes QuickTime Bug
A new security patch for QuickTime has been released by Apple, making it the eight update for this year for the media player software. The update addresses three critical security flaws in Quicktime that also includes a vulnerability that has been used by online criminals.
The most critical of the flaws patched is the implementation of QuickTime of the Real Time Streaming Protocol, or RTSP, which is used to play video and audio over the internet. Attackers began exploiting the flaw early December after it was made public last November. The online attack includes tricking victims into visiting a malicious website that exploited the flaw, and hackers were able to install malicious software on the victims' PCs.
These attacks have targeted Windows-based systems, but experts says that Mac OS X users are also at risk. Apple issued patches for both Windows and Mac OS X users last Thursday.
Security researchers are looking at the way QuickTime works with QuickTime Media Link (QTL) fire format used by the media player. The second critical vulnerability, which had apparently not been publicly disclosed, has to do with this file format.
Apple also patched a handful of similar bugs in the way that QuickTime handles Adobe's Flash media format. The most serious of these flaws could let attackers run unauthorized software on the computer, much as the RTSP bug does, Apple said.
With security researchers paying special attention to media format bugs, Apple has had to patch QuickTime frequently this year. Some of these updates have come just weeks apart. Apple last patched QuickTime on Nov. 5.
Monday, December 10, 2007
Microsoft to Release 7 Patches
The last batch of updates this year focuses on security fixes for Windows and Internet Explorer.
A Round of Patches from Microsoft
Microsoft corporation promised to end the year with a bang by scheduling
seven security updates Tuesday to fix flaws in Windows and Internet Explorer.
Even though Microsoft pledged that Windows Vista, the year-old operating system, is the most secure version of Windows ever, it will still be affected by five of the seven updates. "That's no small percentage," noted Andrew Storms, director of security operations at nCircle Inc. "The perpetuates the fact that even though Microsoft said it was secure, it still needs plenty of patches."
Three of the seven updates will be rated "critical" - Microsoft's highest ranking, while the remaining four will be labeled "important", the next lower rating. Microsoft has revealed limited amount of information about the updates in a prepatch notification posted to its website last Sunday.
One of the seven is a sure bet, Storms said, referring to an update for Windows dubbed as important that will affect Windows XP, and Windows Server 2003. "The Macrovision patch is the most likely candidate for what they're calling bulletin 5," said Storms.
Early last month, Microsoft confirmed that attackers were actively exploiting a bug in third-party anti-piracy software bundled with Windows. The software, which Microsoft licenses from Macrovision Inc., had been updated for Vista, which was why that OS was not at risk. Although Macrovision quickly issued a replacement driver for Windows XP and Server 2003, Microsoft said it needed time to prepare and test the update, which meant it missed the November patch deadline.
"The rest of these are a complete surprise to me," admitted Storms. With one exception, he also hesitated at guessing the contents of the remaining half-dozen updates. His one prediction: "Bulletin 7 might be the fix for the WPAD vulnerability."
On Monday, the Microsoft Security Response Center advised users of a bug in the way Windows looks up other computers on the Internet that has resurfaced. The flaw could allow attackers to steer users to an untrustworthy Web Proxy Auto-Discovery (WPAD) server, where they would receive directions to, say, malicious Web sites rather than the legitimate destinations.
"That would be a very quick fix, and unlikely Microsoft behavior, but if the fix is as simple as some have said, it's possible," said Storms.
Unless it yanks one or more from the list at the last minute, Microsoft will end the year having released 69 security bulletins in 2007, nine fewer than 2006's total but 14 more than in 2005.
Posted by
Ran Werkheiser
at
18:20
0
comments
Labels: internet explorer, microsoft, patch, windows vista, windows xp
Saturday, December 8, 2007
Microsoft Internet Explorer Flaw
Microsoft acknowledges that there is a vulnerability with Internet Explorer 7 and rushes out fix
Microsoft IE7 to Patch
Microsoft went to work to fix a vulnerability with Windows Internet Explorer and its URI, or Uniform Resource Identifier. The fix is to address the problem in the way Internet Explorer 7 interacts with other programs. But with no fix available at the time, using IE7 on Windows XP machines is risky business.
The vulnerability of IE 7 lies in how it interacts, via the URI handler, with products such as Adobe's Acrobat Reader or Mozilla's Firefox. Before, Microsoft pointed fingers to Firefox. Then, the company, after acknowledging that the problem was its own, went to a slow work on a fix because no known exploit existed at the time. But it went on a frenzy when a Trojan horse attack started infecting machines in October.
The Trojan horse attack, which a user receives as an infected PDF, brings an old social-engineerin ploy, which malware filters usually don't vet. It tricks you into clicking the link by carrying a subject line such as "invoice" or "bill".
Adobe patched Reader, but that only covers one end of the worm home. Microsoft's patch has been in testing for quite a while, and may remain in that state for some time. As of now, try to avoid using Windows Internet Explorer 7 to browse sites that are suspicious. Try other alternatives, such as Firfox version 2.0.0.6 and up, which already has a patch for the URI vulnerability.
Opening e-mail attachements is growing riskier. A Microsoft report found that the first half of 2007 saw a 150 rcent increase in phishing scams and a 500 percent increase in malicous payloads.
Obtain a patch of Adobe Reader fix at the Adobe's site if you don't have the PDF fix yet.
Posted by
Ran Werkheiser
at
19:36
0
comments
Labels: adobe, flaw, internet explorer, microsoft, online security, patch
Wednesday, December 5, 2007
PC + Mac QuickTime Flaw
Symantec warns that both Windows and Mac systems may be vulnerable to exploits of an unpatched Quicktime flaws
Windows and Mac Shares QuickTime Flaw
Last Sunday, Symantec warned in a DeepSight Threat Management System alert that attackers are trying to exploit an unpatched vulnerability in Apple's QuickTime software that could let them run code on a victim's computer.
Attackers appear to be aimed at Windows users, but Mac OS users could be open to the risk as well, as QuickTime vulnerability in question affects both operating systems. The vulnerability, called the Apple QuickTime RTSP Response Header Stack-Based Buffer Overflow Vulnerability, was first revealed on November 23, and still remains unpatched by Apple.
Windows XP and Windows Vista running Internet Explorer, Firefox, Opera, and Safari are affected by this vulnerability, as well as Apple's own MacOS X 10.4 and 10.5.
Symantec said that there are two types of attacks underway. One involves redireting the victim's computer from an adult web site, Ourvoyeur.net, to another web site that infects the computer with an application called loader.exe. It can be saved to the victim's computer as metasploit.exe, asasa.exe, or syst.exe. Once installed on a computer, this application downloads another binary file, which Symantec identified as Hacktool.Rootkit, a set of tools that can be used to break into a system. It's possible that Ourvoyer.net was compromised as part of the attack.
The second method of attack also involves redirection, however, Symantec is currently investigating the attack to determine what, if any, malicious code is involved.
To protect systems from attack, Symantec recommended blocking access to affected sites. "Filter outgoing access to 85.255.117.212, 85.255.117.213, 216.255.183.59, 69.50.190.135, 58.65.238.116, and 208.113.154.34. Additionally 2005-search.com, 1800-search.com, search-biz.org, and ourvoyeur.net should be filtered," it said, adding IT managers can also block outgoing TCP access to port 554.
Alternatively, IT managers could take more drastic steps. "As a last measure, QuickTime should be uninstalled until patches are available," the alert said.
Posted by
Ran Werkheiser
at
18:47
0
comments
Labels: apple, bug, flaw, mac, patch, quicktime, symantec, windows xp