Feeds

Patch Tuesday: And EVERY version of IE needs fixing AGAIN

Adobe, VMware join Microsoft in the stocks this month

3 Big data security analytics techniques

June's Black Tuesday patch update from Microsoft has rolled into town with five bulletins, including a solitary critical update that tackles flaws in all supported versions of Internet Explorer.

The IE update (MS13-047) grapples with 19 vulnerabilities and covers all versions of IE, from IE6 to IE10, on all supported versions of Windows, from XP to RT. It's just the sort of thing that might be latched onto by hackers as part of drive-by-download attacks, based on malicious scripts on compromised websites, and therefore needs to be patched sooner rather than later.

The other four bulletins this week all cover lesser flaws, rated "important" by Microsoft. The most noteworthy of these is (MS13-051) which covers Microsoft Office 2003 on Windows and 2011 for Mac OS X and tackles a parsing vulnerability for the PNG graphic format that has already cropped up in a limited number of active attacks.

"The attack arrives in an Office document and is triggered when the user opens the document," writes Wolfgang Kandek, CTO at cloud security firm Qualys. "Microsoft rates it only as 'important' because user interaction is required, but attackers have shown over and over that getting a user to open a file is quite straightforward."

The remaining three "important" updates from Microsoft tackle an information disclosure vulnerability within the Windows kernel, a local privilege escalation vulnerability within the print spooler components in Windows, and a DoS problem in the TCP/IP stack of newer Windows systems. Taken altogether it's a fairly quiet month.

Microsoft's Patch Tuesday bulletin for June can be found here. A graphical overview from the SANS Institute's Internet Storm Centre team can be found here.

June's patch update from Microsoft omits to fix a recent 0-day vulnerability discovered by Google's Tavis Ormandy. The 0-day vulnerability allows an attacker already on a Windows machine to gain admin privileges.

In related patching news, Adobe is pushing out an updated version of Flash (APSB13-16), that will be released to Google Chrome or Microsoft IE10 users via an automatic update. In other cases the cross-platform update - which covers versions of Flash Player on Windows, Macs and Linux as well as Android smartphones - will need to be applied separately.

Meanwhile server and datacentre admins would do well to pay attention to the release of a security bulletin from VMware, covering a vulnerability in handling file uploads by the vCenter Chargeback Manager that poses a remote code execution risk on unlatched systems.

Apple pushed out its own quarterly security fixes last week, with new version of Safari and Mac OS X addressing numerous critical vulnerabilities. These security updates are unrelated to the new versions of Mac OS X and Safari announced at this week's WWDC in San Francisco, which will not be released for some time yet. ®

3 Big data security analytics techniques

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Putin tells Snowden: Russia conducts no US-style mass surveillance
Gov't is too broke for that, Russian prez says
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
Mounties always get their man: Heartbleed 'hacker', 19, CUFFED
Canadian teen accused of raiding tax computers using OpenSSL bug
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
Arts and crafts store Michaels says 3 million credit cards exposed in breach
Meanwhile, Target investigators prepare for long process in nabbing hackers
prev story

Whitepapers

Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.