Feeds

Patch Tuesday sounds death knell for Win XP SP2

Hasta la vista

Using blade systems to cut costs and sharpen efficiencies

Microsoft released the expected four security advisories on Tuesday, three of which earn the dread rating of critical. They collectively address five security vulnerabilities.

There are two critical fixes for Windows in the batch, including an update designed to resolve a zero-day vulnerability involving Windows Help and Support Centre that's become a hackers' favourite over recent weeks. The vulnerability was controversially disclosed by Google staffer Tavis Ormandy prior to Microsoft providing a fix.

The other two critical updates cover flaws in Microsoft Access ActiveX component and the CDD display driver for Windows 7 and Windows 2008R2. Lesser risk "important" updates cover security bugs in the handling of attachments by Microsoft Outlook.

Tyler Reguly, senior security engineer at security firm nCircle, described July's patches as "pretty mundane" in terms of corporate security.

"The most interesting vulnerability for the enterprise is MS10-045, which lets an attacker use a specially-crafted UNC path in an Outlook attachment to bypass Outlook’s warning about opening potentially malicious attachments," Reguly said. "This is significant because Operation Aurora and other high profile email based attacks over the last year have proven to be highly successful."

The Internet Storm Centre has once again put together a handy overview of Microsoft's latest Patch Tuesday update here. Microsoft's bulletin is here.

July 2010's Patch Tuesday marked the last month Microsoft will issue patches for either Windows XP Service Pack 2 and Win 2000. Security watchers reckon a significant proportion of Windows machines are still running Win XP SP2.

"Since Windows XP is still the most popular OS version for Windows, I believe we’re dealing with hundreds of millions of Windows XP SP2 systems that need to be upgraded," said Wolfgang Kandek, CTO of Qualys. "Our own monitoring shows that roughly 50 percent of all XP machines still run on the SP2 version. XP SP2 machines can be found both in corporate installations and are also very often the OS on home machines." ®

The smart choice: opportunity from uncertainty

More from The Register

next story
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Do YOU work at Microsoft? Um. Are you SURE about that?
Nokia and marketing types first to get the bullet, says report
Microsoft takes on Chromebook with low-cost Windows laptops
Redmond's chief salesman: We're taking 'hard' decisions
Cheer up, Nokia fans. It can start making mobes again in 18 months
The real winner of the Nokia sale is *drumroll* ... Nokia
EU dons gloves, pokes Google's deals with Android mobe makers
El Reg cops a squint at investigatory letters
Chrome browser has been DRAINING PC batteries for YEARS
Google is only now fixing ancient, energy-sapping bug
Big Blue Apple: IBM to sell iPads, iPhones to enterprises
iOS/2 gear loaded with apps for big biz ... uh oh BlackBerry
prev story

Whitepapers

Reducing security risks from open source software
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.