Security firms issue Patch Tuesday warnings

Powered by SC Magazine
 

Latest updates need careful consideration.

Security firms are warning of a number of serious issues to consider with Microsoft's latest security update.

Microsoft released patches for just two vulnerabilities in this month's update which, although rated critical, represent a much smaller load on IT managers compared with previous Patch Tuesday releases.

Alan Bentley, vice president at security firm Lumension, reminded companies that Microsoft had missed one important issue from this release.

"No patch has been made available for the SharePoint vulnerability, and Microsoft is directing users to Security Advisory 983438 as a workaround pending release of a patch," he said.

Wolfgang Kandek, chief technology officer at Qualys, recommended looking into the advisory and implementing the suggested workaround which restricts access to the Help functionality in SharePoint.

Lumension's Bentley also pointed out that a vulnerability with Safari remains unpatched, and warned that proof-of-concept code that could be used to exploit it is "freely available on the internet".

He added that Safari is often installed "silently" along with QuickTime, for example, meaning that in some cases users are unaware that the Apple browser is on their systems.

Symantec was most concerned with the Microsoft patches, however. Joshua Talbot, security intelligence manager at Symantec Security Response, said that staff education is critical, particularly as both potential issues require an element of social engineering to work.

"An attacker would simply have to convince a user to open a maliciously craft ed file, likely an Office document, which supports VBA and the user's machine would be compromised. I can see this being used in targeted attacks, which are on the rise," he said.

Talbot also urged IT admins not to be complacent about the small number of Microsoft patches this month.

"Lately, Microsoft seems to be alternating between light patching one month and then heavy the next," he said. "So, one has to wonder what next month holds in store."

All of the security companies urged enterprises to install the fixes as soon as possible, adding that many would require system restarts.

Graham Cluley, senior technology consultant at Sophos, said that Adobe had also released fixes this month covering 20 issues, including one affecting Shockwave which could allow remote execution on Windows and Mac platforms.

Copyright ©v3.co.uk


Security firms issue Patch Tuesday warnings
 
 
 
Top Stories
Turnbull introduces data retention legislation
Still no definition of metadata to be stored.
 
Images: the next frontier in data analytics?
Barclay’s global data chief says we’re still at the starting line.
 
Crime Commission prepares core systems overhaul
Will replace 30 year-old national criminal database.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
Do you direct debit customers? Read this
Oct 10, 2014
Authorities have been targeting direct debit practices with iiNet and Dodo receiving formal ...
Optus expands 4G coverage
Oct 10, 2014
If you rely on an Optus phone for work you might be interested to know that there are now 200 ...
Microsoft Office is now free for some charities
Oct 10, 2014
Microsoft has announced that eligible Australian non-profit organisations and charities can now ...
Vodafone lights up 4G in Adelaide
Oct 9, 2014
Live and work in Adelaide? Vodafone has switched on its 4G network in the city and suburbs.
Next year tradies will be able to take payments using ingogo
Oct 3, 2014
Ingogo is going to provide a card payment service for Xero users.
Latest Comments
Polls
In which area is your IT shop hiring the most staff?




   |   View results
IT security and risk
  27%
 
Sourcing and strategy
  12%
 
IT infrastructure (servers, storage, networking)
  21%
 
End user computing (desktops, mobiles, apps)
  15%
 
Software development
  25%
TOTAL VOTES: 417

Vote
Would your InfoSec team be prepared to share threat data with the Australian Government?

   |   View results
Yes
  55%
 
No
  45%
TOTAL VOTES: 196

Vote