Security firms issue Patch Tuesday warnings

Powered by SC Magazine
 

Latest updates need careful consideration.

Security firms are warning of a number of serious issues to consider with Microsoft's latest security update.

Microsoft released patches for just two vulnerabilities in this month's update which, although rated critical, represent a much smaller load on IT managers compared with previous Patch Tuesday releases.

Alan Bentley, vice president at security firm Lumension, reminded companies that Microsoft had missed one important issue from this release.

"No patch has been made available for the SharePoint vulnerability, and Microsoft is directing users to Security Advisory 983438 as a workaround pending release of a patch," he said.

Wolfgang Kandek, chief technology officer at Qualys, recommended looking into the advisory and implementing the suggested workaround which restricts access to the Help functionality in SharePoint.

Lumension's Bentley also pointed out that a vulnerability with Safari remains unpatched, and warned that proof-of-concept code that could be used to exploit it is "freely available on the internet".

He added that Safari is often installed "silently" along with QuickTime, for example, meaning that in some cases users are unaware that the Apple browser is on their systems.

Symantec was most concerned with the Microsoft patches, however. Joshua Talbot, security intelligence manager at Symantec Security Response, said that staff education is critical, particularly as both potential issues require an element of social engineering to work.

"An attacker would simply have to convince a user to open a maliciously craft ed file, likely an Office document, which supports VBA and the user's machine would be compromised. I can see this being used in targeted attacks, which are on the rise," he said.

Talbot also urged IT admins not to be complacent about the small number of Microsoft patches this month.

"Lately, Microsoft seems to be alternating between light patching one month and then heavy the next," he said. "So, one has to wonder what next month holds in store."

All of the security companies urged enterprises to install the fixes as soon as possible, adding that many would require system restarts.

Graham Cluley, senior technology consultant at Sophos, said that Adobe had also released fixes this month covering 20 issues, including one affecting Shockwave which could allow remote execution on Windows and Mac platforms.

Copyright ©v3.co.uk


Security firms issue Patch Tuesday warnings
 
 
 
Top Stories
Inside the stalemate on Australia's piracy code
Still not registered almost five months on.
 
IT staff outline deep anger in Macquarie Uni survey
‘Morale at lowest point in a decade’.
 
Cost blowout to push NBN past $41bn budget
But government funding cap to remain.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
Say goodbye to OneDrive Groups
Aug 28, 2015
If you've a) actually been using OneDrive and b) gone so far as to actually have been using ...
Libreoffice 5 review
Aug 24, 2015
It's free! It's open! But does LibreOffice deliver on its promise of a powerful office suite for ...
How to disable Cortana in Windows 10
Aug 21, 2015
Stop Microsoft's personal assistant snooping around.
Uni is optional: 5 tech leaders without a degree
Aug 17, 2015
Already running a business, but thinking about going back to uni? From Bill Gates to Steve Jobs, ...
New features coming to Xero
Aug 17, 2015
Use Xero? Here are some of the things you can look forward to in the coming months.
Latest Comments
Polls
New Windows 10 users, are you upgrading from...




   |   View results
Windows 8
  47%
 
Windows 7
  44%
 
Windows XP
  5%
 
Another operating system
  3%
 
Windows Vista
  2%
TOTAL VOTES: 705

Vote