Microsoft delivers six patches

Powered by SC Magazine
 

"Critical" Windows kernel bug of most concern.

Microsoft has patched for 15 vulnerabilities with the distribution of six bulletins, one of which the software giant recommends administrators immediately apply.

That fix, MS09-065, corrects three vulnerabilities in Windows kernel-mode drivers. One of the flaws is considered "critical", but does not impact Vista or Server 2008.

The bug, however, can be exploited on Windows 2000, XP and Server 2003 machines to execute remote code if a user views content rendered in a maliciously-crafted Embedded OpenType font, used on web pages. Proof-of-concept code is already available to launch drive-by attacks, security researchers said yesterday. And, according to Microsoft, consistent exploit code is expected.

"We recommend customers prioritize and deploy this update immediately," Jerry Bryant, senior security program manager at Microsoft, wrote on the company's Security Response Center blog.

Ben Greenbaum, senior research manager at Symantec, agreed that the bulletin should be urgently deployed because the flaw is at the kernel level, meaning it does not matter with what privilege the user's machine is running.

"All that's required of a user to become infected by it is simply viewing a compromised web page," he said. "Symantec isn't seeing any active exploits of this in the wild yet, but we think attackers will be paying a lot of attention to it in the future."

Tuesday's update also includes two other "critical" bulletins, which address four vulnerabilities, and three "important" bulletins that take care of 10 bugs. One of those -- MS09-067 -- resolves eight flaws in Office that can lead to remote code execution if a user opens a specially-crafted Excel file.

Sheldon Malm, senior director of security strategy at Rapid7, a vulnerability management provider, called MS09-067 a "sleeper threat" because Microsoft considers it highly exploitable and because Excel is widely used.

Also, as part of the update, Microsoft re-released two patches: MS09-045 and MS09-051.

See original article on scmagazineus.com

Copyright © SC Magazine, US edition


 
 
 
Top Stories
Innovating in the sleepy super industry
There’s little incentive to be on the bleeding edge, so why is Andrew Todd fighting so hard?
 
How technology will unify Toll
The systems headache formed through 15 years of acquisitions.
 
Immigration breached Privacy Act with data leak
Pilgrim slams "copy and paste" of asylum seeker data.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
Optus steps up regional 4G coverage
Nov 20, 2014
Once 700Mhz services are working, Optus claims regional users will have a "faster and more ...
This Huawei 4G phone costs $99
Nov 12, 2014
The $99 Huawei Ascend Y550, available through Vodafone, enters the budget market as one of the ...
4G smartphones: Microsoft's Lumia 830
Nov 7, 2014
Microsoft has announced its flagship Windows Phone, the Nokia Lumia 830 4G, will be available in ...
Do you direct debit customers? Read this
Oct 10, 2014
Authorities have been targeting direct debit practices with iiNet and Dodo receiving formal ...
Optus expands 4G coverage
Oct 10, 2014
If you rely on an Optus phone for work you might be interested to know that there are now 200 ...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  39%
 
Your insurance company
  3%
 
A technology company (Google, Facebook et al)
  7%
 
Your telco, ISP or utility
  7%
 
A retailer (Coles, Woolworths et al)
  2%
 
A Federal Government agency (ATO, Centrelink etc)
  20%
 
An Australian law enforcement agency (AFP, ASIO et al)
  15%
 
A State Government agency (Health dept, etc)
  6%
TOTAL VOTES: 786

Vote