Feeds

Nine MS security bulletins create busy updates workload

Patches needed for almost everything - except IE

Internet Security Threat Report 2014

Microsoft released the expected nine patches - five critical - as part of a busy August Patch Tuesday update that focuses primarily on client-side vulnerabilities.

The bulletins collectively address 19 security flaws. The batch includes a bulletin covering a flaw in Office Web Components (MS09-043) that has served as the fodder for active hacking attacks since June. Users are open to attack if they stray onto sites hosting exploit code. A separate critical update for Windows Media Player (MS09-038) addresses a flaw that created a means to hack systems after tricking users into playing malformed AVI files.

Another update fixes five ActiveX controls that were made using a vulnerable version of the ATL library template. The root cause of this flaw - which has affected third party applications developers such as Adobe as much as Microsoft - was addressed in the MS09-035 out of sequence update in late July.

Flaws in Remote Desktop Protocol (RDP - formerly known as Terminal Services) that create a drive-by download attack risk are also addressed in the patch Batch.

On the server-side, the worst of the critical flaws addresses a severe threat for WINS servers on Microsoft networks. The flaw creates a means to mount an unauthenticated server-side attack. Providing an attacker can smuggle malicious packets past a firewall, the bug, if left unaddressed, creates a means to execute arbitrary code on a server.

Other "important updates" address flaws in Workstation service, Windows Message Queuing Service (MSMQ) services, Telnet and a denial of service vulnerability in ASP.NET.

A Microsoft summary can be found here, and an easier to digest "Black Tuesday" overview from the SANS Institute's Internet Storm Centre can be found here. Microsoft's summary of affected software reveals that all supported versions of Windows (client and server) will need updates for one reason or another. Office suites also need patching because of the Office Web Components flaw, which affects server applications including BizTalk and ISAS.

Eric Schultze, CTO at patch management firm Shavlik and a former programme manager for the Microsoft Security Response Centre, explained: "The bulletins cover a gamut of affected products - almost everything in your enterprise will need to be patched today with the exception of Internet Explorer."

Wolfgang Kandek, CTo at vulnerability assessment firm Qualys, commented: "There are five critical patches that can all be exploited remotely and four important ones that require direct access to the system for exploitation."

"Although this is a big release, there are no surprises in it as it addresses an outstanding public zero-day vulnerability and it includes an official patch for the out-of-band patch released in July for MS09-034. As always users are urged to review these critical patches carefully against their environment and apply them as soon as possible," he added. ®

Internet Security Threat Report 2014

More from The Register

next story
George Clooney, WikiLeaks' lawyer wife hand out burner phones to wedding guests
Day 4: 'News'-papers STILL rammed with Clooney nuptials
Shellshock: 'Larger scale attack' on its way, warn securo-bods
Not just web servers under threat - though TENS of THOUSANDS have been hit
Apple's new iPhone 6 vulnerable to last year's TouchID fingerprint hack
But unsophisticated thieves need not attempt this trick
PEAK IPV4? Global IPv6 traffic is growing, DDoS dying, says Akamai
First time the cache network has seen drop in use of 32-bit-wide IP addresses
Oracle SHELLSHOCKER - data titan lists unpatchables
Database kingpin lists 32 products that can't be patched (yet) as GNU fixes second vuln
Who.is does the Harlem Shake
Blame it on LOLing XSS terroristas
Researchers tell black hats: 'YOU'RE SOOO PREDICTABLE'
Want to register that domain? We're way ahead of you.
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
The next step in data security
With recent increased privacy concerns and computers becoming more powerful, the chance of hackers being able to crack smaller-sized RSA keys increases.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.