Microsoft delivers six patches

Powered by SC Magazine
 

"Critical" Windows kernel bug of most concern.

Microsoft has patched for 15 vulnerabilities with the distribution of six bulletins, one of which the software giant recommends administrators immediately apply.

That fix, MS09-065, corrects three vulnerabilities in Windows kernel-mode drivers. One of the flaws is considered "critical", but does not impact Vista or Server 2008.

The bug, however, can be exploited on Windows 2000, XP and Server 2003 machines to execute remote code if a user views content rendered in a maliciously-crafted Embedded OpenType font, used on web pages. Proof-of-concept code is already available to launch drive-by attacks, security researchers said yesterday. And, according to Microsoft, consistent exploit code is expected.

"We recommend customers prioritize and deploy this update immediately," Jerry Bryant, senior security program manager at Microsoft, wrote on the company's Security Response Center blog.

Ben Greenbaum, senior research manager at Symantec, agreed that the bulletin should be urgently deployed because the flaw is at the kernel level, meaning it does not matter with what privilege the user's machine is running.

"All that's required of a user to become infected by it is simply viewing a compromised web page," he said. "Symantec isn't seeing any active exploits of this in the wild yet, but we think attackers will be paying a lot of attention to it in the future."

Tuesday's update also includes two other "critical" bulletins, which address four vulnerabilities, and three "important" bulletins that take care of 10 bugs. One of those -- MS09-067 -- resolves eight flaws in Office that can lead to remote code execution if a user opens a specially-crafted Excel file.

Sheldon Malm, senior director of security strategy at Rapid7, a vulnerability management provider, called MS09-067 a "sleeper threat" because Microsoft considers it highly exploitable and because Excel is widely used.

Also, as part of the update, Microsoft re-released two patches: MS09-045 and MS09-051.

See original article on scmagazineus.com

Copyright © SC Magazine, US edition


 
 
 
Top Stories
Westpac committed to core banking plan
[Blog post] Now with leadership.
 
The True Cost of BYOD - 2014 survey
Twelve months on from our first study, is BYOD a better proposition?
 
Photos: Unboxing the Magnus supercomputer
Pawsey's biggest beast slots into place.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
Pass on carbon tax savings, warns ACCC
Jul 24, 2014
The ACCC is warning businesses that supply "regulated goods" to pass on any cost savings ...
Have customers that won't pay debts?
Jul 10, 2014
The ACCC and ASIC have updated their advice when it comes to collecting debts.
Carpet cleaner faces court over online testimonials
Jul 4, 2014
The ACCC has initiated proceedings against A Whistle (1979) Pty Ltd, the franchisor of Electrodry...
You can now get 15GB of free online storage using Microsoft OneDrive
Jun 25, 2014
Cloud storage has reached both the capacity and price where it's a viable alternative to local ...
Another clever trick you can perform with Xero
Jun 25, 2014
Here is another way to reach out to particular subsets of your customers using Xero.
Latest Comments
Polls
What is delaying adoption of public cloud in your organisation?







   |   View results
Lock-in concerns
  29%
 
Application integration concerns
  3%
 
Security and compliance concerns
  27%
 
Unreliable network infrastructure
  9%
 
Data sovereignty concerns
  22%
 
Lack of stakeholder support
  3%
 
Protecting on-premise IT jobs
  4%
 
Difficulty transitioning CapEx budget into OpEx
  3%
TOTAL VOTES: 1141

Vote