Microsoft pushes nine fixes for 16 flaws

Powered by SC Magazine
 

Gaping Core XML Services hole fixed.

Microsoft on Tuesday issued nine security bulletins to address three "critical" and six "important" security issues.

The patches righted 16 flaws in Windows, Internet Explorer, Office, SharePoint, and Visual Basic for Applications.

Yunsun Wee of Microsoft Trustworthy Computing recommended organisations prioritise patching the three critical updates first, which includes a fix for the zero-day vulnerability in Microsoft Core XML Services (MSXML) that was disclosed in early June. Attackers have been targeting the vulnerability already, and exploit code has been added to the BlackHole malware toolkit and to the Metasploit penetration testing framework.

"[Bulletin] MS12-046 has the fix that IT folks have been waiting a month for," Marc Maiffret, CTO of identity management company BeyondTrust, told SCMagazine.com.

However, the update applies to only MSXML versions 3, 4, and 6. The fix for MSXML 5 is expected at a later date as the Microsoft team has not yet finished testing the patch, so organisations running Office 2003 and 2007, Office Word Viewer, Expression Web Edition, Office SharePoint Server 2007, and Groove Server 2007 are left unprotected, Maiffret said.

Since MSXML 5 is not on the pre-approved ActiveX controls list, users should see a big warning when browsing to a site that tries to load the MSXML 5 ActiveX control so they would notice when they are being targeted, he said.

Microsoft issued a Fix-It document shortly after disclosing the flaw, which outlined some mitigation activities organizations can apply while waiting for the patch. Organizations with version 5 should implement the Fix-It if they haven't already done so, Maiffret said.

Meanwhile, the cumulative update for Internet Explorer 9 addresses two critical vulnerabilities and should be applied immediately. 

"Both can be triggered through a malicious web page, and both allow the attacker remote code execution, [meaning] full control of the targeted machine," said Wolfgang Kandek, CTO of vulnerability management firm Qualys. Microsoft assigned an Exploitability Index rating of 1 to these bugs, which means the company believes attackers would be able to easily reverse engineer the patch and develop an exploit within 30 days.

The third critical bulletin is an update for the Microsoft Data Access Component (MDAC) in Microsoft Windows. The most likely attack vector is through the web browser, Kaspersky Lab's Kurt Baumgartner said. This flaw is "reminiscent" of an older MDAC vulnerability which was added to several popular exploit toolkits and is still seen in attacks, Baumgartner said. 

Maiffret agreed. "This new MDAC vulnerability looks to be something that also will make its way into exploit toolkits sooner than later given it affects most OSs and is a straight forward to exploit."

Along with the patches, Microsoft also issued two security advisories. The first described changes in how the software giant will handle certificates and the upcoming certificate management tool for recent versions of Windows.

RSA certificates with fewer than a 1,024-bit key length will be considered insecure by default, according to the advisory. The new certificate management tool will allow Microsoft to react more rapidly to certificate problems, such as the one that enabled the Flame virus to spread.

The second advisory offers users a tool to disable "Gadgets" in Windows Vista and 7 as support is being discontinued by Microsoft. Gadgets will not exist in Windows 8.

This article originally appeared at scmagazineus.com

Copyright © SC Magazine, US edition


Microsoft pushes nine fixes for 16 flaws
 
 
 
Top Stories
ATO releases long-awaited Bitcoin guidance
Everyday investors escape the tax man.
 
Why the Weather Bureau’s new supercomputer is a 'gamechanger'
IT transformation starts to reap results.
 
Sydney Trains chief thinks beyond Opal
Plots app to help you find a seat on the train.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
Run a small business in western Sydney?
Aug 15, 2014
This event might be of interest if you're looking to meet other people with a similar interest ...
Buying a tablet? Microsoft's Surface Pro 3 goes on sale this month
Aug 8, 2014
Microsoft has announced its Surface Pro 3 will go on sale in Australia on 28 August from ...
Apple's top MacBook Pro with Retina is now cheaper
Aug 1, 2014
Apple has updated its MacBook Pro range with faster processors and new pricing, including ...
Pass on carbon tax savings, warns ACCC
Jul 24, 2014
The ACCC is warning businesses that supply "regulated goods" to pass on any cost savings ...
Have customers that won't pay debts?
Jul 10, 2014
The ACCC and ASIC have updated their advice when it comes to collecting debts.
Latest Comments
Polls
Which is the most prevalent cyber attack method your organisation faces?




   |   View results
Phishing and social engineering
  65%
 
Advanced persistent threats
  3%
 
Unpatched or unsupported software vulnerabilities
  12%
 
Denial of service attacks
  7%
 
Insider threats
  12%
TOTAL VOTES: 403

Vote