Microsoft update misses Word kernel hole

Powered by SC Magazine
 

Duqu survives as Microsoft stomps four nasty bugs.

Microsoft is prepping four bulletins -- each to address one vulnerability -- as part of the software giant's November security update coming Tuesday.

Expected to remain outstanding this patch cycle is the zero-day, Windows kernel flaw believed to be connected to Duqu, the so-called "son of Stuxnet" trojan, according to experts.

Microsoft said it is working to address the issue, though it has not provided a timeline for a fix nor publicly confirmed the vulnerability.

One of the bulletins Microsoft plans to release is rated “critical,” Microsoft's highest bug severity rating, reserved for flaws that could allow the propagation of an internet worm without user action, according to Microsoft's advance notification, released Thursday.

Two other patches are deemed “important,” as they could lead to remote code execution and elevation of privileges, while one is rated “moderate” and could allow for denial-of-service.  

All of the patches impact Windows and will require a reboot.

As for Duqu, Microsoft will likely issue an advisory within the next day or so and provide a hotfix for the flaw, said Paul Henry, security and forensic analyst at endpoint security software firm Lumension.

“While many dispute the threat imposed by this bug, no one disputes the risk of the zero-day vulnerability in Microsoft software that it takes advantage of,” Henry said.  

Some security experts are at odds over whether Duqu should be considered as worrisome as Stuxnet.

This article originally appeared at scmagazineus.com

Copyright © SC Magazine, US edition


Microsoft update misses Word kernel hole
 
 
 
Top Stories
Earning the right to innovate
Breaking down the barriers to innovation is a long, but rewarding process, says Bank of Queensland Group CIO, Julie Bale.
 
A call for timely reporting
[Blog post] Businesses need incentives to keep customer data secure.
 
Doubts cast on Queensland's ICT Dashboard
Opposition, former Govt CIO say it can't be trusted.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
Have customers that won't pay debts?
Jul 10, 2014
The ACCC and ASIC have updated their advice when it comes to collecting debts.
Carpet cleaner faces court over online testimonials
Jul 4, 2014
The ACCC has initiated proceedings against A Whistle (1979) Pty Ltd, the franchisor of Electrodry...
You can now get 15GB of free online storage using Microsoft OneDrive
Jun 25, 2014
Cloud storage has reached both the capacity and price where it's a viable alternative to local ...
Another clever trick you can perform with Xero
Jun 25, 2014
Here is another way to reach out to particular subsets of your customers using Xero.
Have a phone, tablet and laptop?
Jun 20, 2014
This new Telstra pre-paid 4G mobile hotspot might be useful if you regularly need to use fast ...
Latest Comments
Polls
What is delaying adoption of public cloud in your organisation?







   |   View results
Lock-in concerns
  26%
 
Application integration concerns
  3%
 
Security and compliance concerns
  29%
 
Unreliable network infrastructure
  9%
 
Data sovereignty concerns
  22%
 
Lack of stakeholder support
  3%
 
Protecting on-premise IT jobs
  5%
 
Difficulty transitioning CapEx budget into OpEx
  3%
TOTAL VOTES: 857

Vote