Feeds

Bumper MS patch batch spells client-side misery

IE still vulnerable after bombardment

The Essential Guide to IT Transformation

Microsoft issued eight updates on Tuesday - two more than expected - as part of its Patch Tuesday update cycle.

Redmond classifies six of the octet as critical, while independent security watchers reckon they all make the highest security grade. Worst of the bunch is an update for ActiveX controls that affects Visual Basic 6.0's runtime (MS08-070.

The buffer overflow risk affects Visual Studio, Foxpro, Frontpage and MS Project, along with third party apps that make use of the affected component. Worse still exploit code has been doing the rounds since April.

There's also a cumulative fix for Internet Explorer (MS08-073). But this fails to address an unpatched vulnerability that's already being used to mount drive-by download attacks, albeit on a limited basis. Other critical fixes cover flaws in Microsoft Office, Outlook, Windows Media Player and Windows Explorer.

Two bulletins - rated as important by Microsoft but critical by the SANS Institute's Internet Storm Centre (ISC) - tackle problems involving SharePoint Server and a separate bug involving Windows Media Player.

The updates collectively address 28 vulnerabilities. Microsoft summary can be found here, while the far more readable ISC "Black Tuesday" overview can be found here.

"The Microsoft elves have been busy and delivered everyone plenty of work to do this holiday season," said Andrew Storms, director of security at patching specialists nCircle. "All but one of the bulletins affect client-side applications and include all the usual suspects: IE, Office, ActiveX and GDI.

"Given the number of client side bugs with Microsoft products just patched, everyone should expect the attackers to celebrate the holiday season in their attack strategies."

Patching of systems will require systems updates, but needs to be carried out regardless of the potential inconvenience because of the heightened risk of phishing or malware attacks against unprotected systems, Andrew Clarke, senior vice president at security tools firm Lumension warned.

"Four critical updates (two involving Windows and two Microsoft Word and Excel) affecting four key pieces of software and major applications used within the enterprise, will require reboots to their systems and servers, adding a degree of complexity and disruption to network productivity," Clarke said.

"While it may be tempting to avoid restarting servers and systems especially during this busy time of year, it is imperative that all IT professionals pay particular attention to the critical updates and patch as quickly as business conditions permit." ®

Build a business case: developing custom apps

More from The Register

next story
14 antivirus apps found to have security problems
Vendors just don't care, says researcher, after finding basic boo-boos in security software
'Things' on the Internet-of-things have 25 vulnerabilities apiece
Leaking sprinklers, overheated thermostats and picked locks all online
iWallet: No BONKING PLEASE, we're Apple
BLE-ding iPhones, not NFC bonkers, will drive trend - marketeers
Only '3% of web servers in top corps' fully fixed after Heartbleed snafu
Just slapping a patched OpenSSL on a machine ain't going to cut it, we're told
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Israel's Iron Dome missile tech stolen by Chinese hackers
Corporate raiders Comment Crew fingered for attacks
Tor attack nodes RIPPED MASKS off users for 6 MONTHS
Traffic confirmation attack bared users' privates - but to whom?
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
Researcher sat on critical IE bugs for THREE YEARS
VUPEN waited for Pwn2Own cash while IE's sandbox leaked
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
The Essential Guide to IT Transformation
ServiceNow discusses three IT transformations that can help CIO's automate IT services to transform IT and the enterprise.
Maximize storage efficiency across the enterprise
The HP StoreOnce backup solution offers highly flexible, centrally managed, and highly efficient data protection for any enterprise.