Microsoft pushes nine fixes for 16 flaws

Powered by SC Magazine
 

Gaping Core XML Services hole fixed.

Microsoft on Tuesday issued nine security bulletins to address three "critical" and six "important" security issues.

The patches righted 16 flaws in Windows, Internet Explorer, Office, SharePoint, and Visual Basic for Applications.

Yunsun Wee of Microsoft Trustworthy Computing recommended organisations prioritise patching the three critical updates first, which includes a fix for the zero-day vulnerability in Microsoft Core XML Services (MSXML) that was disclosed in early June. Attackers have been targeting the vulnerability already, and exploit code has been added to the BlackHole malware toolkit and to the Metasploit penetration testing framework.

"[Bulletin] MS12-046 has the fix that IT folks have been waiting a month for," Marc Maiffret, CTO of identity management company BeyondTrust, told SCMagazine.com.

However, the update applies to only MSXML versions 3, 4, and 6. The fix for MSXML 5 is expected at a later date as the Microsoft team has not yet finished testing the patch, so organisations running Office 2003 and 2007, Office Word Viewer, Expression Web Edition, Office SharePoint Server 2007, and Groove Server 2007 are left unprotected, Maiffret said.

Since MSXML 5 is not on the pre-approved ActiveX controls list, users should see a big warning when browsing to a site that tries to load the MSXML 5 ActiveX control so they would notice when they are being targeted, he said.

Microsoft issued a Fix-It document shortly after disclosing the flaw, which outlined some mitigation activities organizations can apply while waiting for the patch. Organizations with version 5 should implement the Fix-It if they haven't already done so, Maiffret said.

Meanwhile, the cumulative update for Internet Explorer 9 addresses two critical vulnerabilities and should be applied immediately. 

"Both can be triggered through a malicious web page, and both allow the attacker remote code execution, [meaning] full control of the targeted machine," said Wolfgang Kandek, CTO of vulnerability management firm Qualys. Microsoft assigned an Exploitability Index rating of 1 to these bugs, which means the company believes attackers would be able to easily reverse engineer the patch and develop an exploit within 30 days.

The third critical bulletin is an update for the Microsoft Data Access Component (MDAC) in Microsoft Windows. The most likely attack vector is through the web browser, Kaspersky Lab's Kurt Baumgartner said. This flaw is "reminiscent" of an older MDAC vulnerability which was added to several popular exploit toolkits and is still seen in attacks, Baumgartner said. 

Maiffret agreed. "This new MDAC vulnerability looks to be something that also will make its way into exploit toolkits sooner than later given it affects most OSs and is a straight forward to exploit."

Along with the patches, Microsoft also issued two security advisories. The first described changes in how the software giant will handle certificates and the upcoming certificate management tool for recent versions of Windows.

RSA certificates with fewer than a 1,024-bit key length will be considered insecure by default, according to the advisory. The new certificate management tool will allow Microsoft to react more rapidly to certificate problems, such as the one that enabled the Flame virus to spread.

The second advisory offers users a tool to disable "Gadgets" in Windows Vista and 7 as support is being discontinued by Microsoft. Gadgets will not exist in Windows 8.

This article originally appeared at scmagazineus.com

Copyright © SC Magazine, US edition


Microsoft pushes nine fixes for 16 flaws
 
 
 
Top Stories
Myer CIO named retailer's new chief executive
Richard Umbers to lead data-driven retail strategy.
 
Empty terminals and mountains of data
Qantas CIO Luc Hennekens says no-one is safe from digital disruption.
 
BoQ takes $10m hit on Salesforce CRM
Regulatory hurdles end cloud pilot.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
Microsoft is offering Azure for Disaster Recovery to Australian SMBs
Feb 10, 2015
If you haven't talked to your IT provider about disaster recovery, it might be worth discussing ...
The 2015 Xero Roadshow is on: here are the locations and dates
Feb 6, 2015
The 2015 Xero Roadshow kicked off this week - see where you can attend at locations around ...
Microsoft Outlook is now on iPhone and iPad: why could this be useful?
Jan 30, 2015
Microsoft today released Office for Android and Outlook for iOS - complementing the other Office ...
Franchisees, here's something you should know about
Jan 23, 2015
You need to know the Code if you are a franchisee or franchisor as the penalties are significant.
Xero users rejoice! Quoting has finally arrived
Jan 23, 2015
It has taken years, but Xero has at last added integrated quoting to its online accounting software.
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  35%
 
Your insurance company
  5%
 
A technology company (Google, Facebook et al)
  9%
 
Your telco, ISP or utility
  8%
 
A retailer (Coles, Woolworths et al)
  4%
 
A Federal Government agency (ATO, Centrelink etc)
  18%
 
An Australian law enforcement agency (AFP, ASIO et al)
  15%
 
A State Government agency (Health dept, etc)
  7%
TOTAL VOTES: 4004

Vote
Do you support the abolition of the Office of the Information Commissioner?

   |   View results
I support shutting down the OAIC.
  27%
 
I DON'T support shutting the OAIC.
  73%
TOTAL VOTES: 1371

Vote