Feeds

Bumper MS patch batch spells client-side misery

IE still vulnerable after bombardment

Build a business case: developing custom apps

Microsoft issued eight updates on Tuesday - two more than expected - as part of its Patch Tuesday update cycle.

Redmond classifies six of the octet as critical, while independent security watchers reckon they all make the highest security grade. Worst of the bunch is an update for ActiveX controls that affects Visual Basic 6.0's runtime (MS08-070.

The buffer overflow risk affects Visual Studio, Foxpro, Frontpage and MS Project, along with third party apps that make use of the affected component. Worse still exploit code has been doing the rounds since April.

There's also a cumulative fix for Internet Explorer (MS08-073). But this fails to address an unpatched vulnerability that's already being used to mount drive-by download attacks, albeit on a limited basis. Other critical fixes cover flaws in Microsoft Office, Outlook, Windows Media Player and Windows Explorer.

Two bulletins - rated as important by Microsoft but critical by the SANS Institute's Internet Storm Centre (ISC) - tackle problems involving SharePoint Server and a separate bug involving Windows Media Player.

The updates collectively address 28 vulnerabilities. Microsoft summary can be found here, while the far more readable ISC "Black Tuesday" overview can be found here.

"The Microsoft elves have been busy and delivered everyone plenty of work to do this holiday season," said Andrew Storms, director of security at patching specialists nCircle. "All but one of the bulletins affect client-side applications and include all the usual suspects: IE, Office, ActiveX and GDI.

"Given the number of client side bugs with Microsoft products just patched, everyone should expect the attackers to celebrate the holiday season in their attack strategies."

Patching of systems will require systems updates, but needs to be carried out regardless of the potential inconvenience because of the heightened risk of phishing or malware attacks against unprotected systems, Andrew Clarke, senior vice president at security tools firm Lumension warned.

"Four critical updates (two involving Windows and two Microsoft Word and Excel) affecting four key pieces of software and major applications used within the enterprise, will require reboots to their systems and servers, adding a degree of complexity and disruption to network productivity," Clarke said.

"While it may be tempting to avoid restarting servers and systems especially during this busy time of year, it is imperative that all IT professionals pay particular attention to the critical updates and patch as quickly as business conditions permit." ®

The essential guide to IT transformation

More from The Register

next story
Rupert Murdoch says Google is worse than the NSA
Mr Burns vs. The Chocolate Factory, round three!
e-Borders fiasco: Brits stung for £224m after US IT giant sues UK govt
Defeat to Raytheon branded 'catastrophic result'
Germany 'accidentally' snooped on John Kerry and Hillary Clinton
Dragnet surveillance picks up EVERYTHING, USA, m'kay?
Snowden on NSA's MonsterMind TERROR: It may trigger cyberwar
Plus: Syria's internet going down? That was a US cock-up
Who needs hackers? 'Password1' opens a third of all biz doors
GPU-powered pen test yields more bad news about defences and passwords
Think crypto hides you from spooks on Facebook? THINK AGAIN
Traffic fingerprints reveal all, say boffins
Microsoft cries UNINSTALL in the wake of Blue Screens of Death™
Cache crash causes contained choloric calamity
prev story

Whitepapers

Endpoint data privacy in the cloud is easier than you think
Innovations in encryption and storage resolve issues of data privacy and key requirements for companies to look for in a solution.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Solving today's distributed Big Data backup challenges
Enable IT efficiency and allow a firm to access and reuse corporate information for competitive advantage, ultimately changing business outcomes.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.