iTnews
  • Home
  • News
  • Technology
  • Security

Microsoft Patch Tuesday fixes 22 vulnerabilities

By Greg Masters
Aug 10 2011 3:31PM
Follow google news

Two critical bulletins, nine important and two moderate.

Microsoft has released fixes for 22 vulnerabilities discovered in Internet Explorer, Windows, Visio and Visual Studio as part of its monthly Patch Tuesday upgrades.

Microsoft Patch Tuesday fixes 22 vulnerabilities

The software giant released 13 security bulletins overnight, two of which are rated critical in severity, nine important and two moderate.

It advised customers to install all of the updates as soon as possible, starting with the two rated most critical.

MS11-057 for Internet Explorer fixed five privately reported vulnerabilities and two publicly disclosed vulnerabilities, according to the release. The most severe of these vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet Explorer.

MS11-058 resolves two privately reported vulnerabilities in Windows DNS server. The more severe of these vulnerabilities could allow remote code execution if an attacker sends a specially crafted Naming Authority Pointer (NAPTR) query to a DNS server. Servers that do not have the DNS role enabled are not at risk, the report said.

"It is interesting to see a big patch day coming after a security conference [Black Hat], instead of before one," Aviv Raff, CTO at cyberthreat management company Seculert, said on Tuesday.

"Usually, vendors patch for zero day before a security conference in order to block security researchers from releasing them." Andrew Storms, director of security at nCircle, a network security and compliance auditing firm, said enterprises should also pay special attention to MS11-064, a bulletin listed by Microsoft as "important".

"Attackers can take advantage of this bug to cause a remote reboot of Windows computers even if they have a local firewall enabled," Storms said. "Back in the early 90s, we used to call this kind of bug the ‘ping of death.'"

It would only take about 10 minutes for an attacker to write and distribute a tool to take advantage of the flaw, Storms said. Then, anyone could easily grab that attack tool and, with a single click, cause a Windows network to reboot.

"The malicious potential is enormous," he said. "The most troubling thing about this bug is that the local Windows firewall does not mitigate the attack."

Service providers like ISPs, cloud providers and others that allow inbound ping packets to their server instances should immediately look for ways to mitigate this bug using edge firewalls, Storms said.

Overall, IT administrators have had their hands full this summer, Dave Marcus, director of security research and communications at McAfee Labs, said.

“Although there are only two critical [Microsoft] patches this month, this update comes after the July patches from Oracle and Apple, and there will be another release of critical patches for Adobe Flash Player [on Tuesday]," he said.

To provide the best protection possible against exploitation, Don Debolt, director of threat research at Total Defense, a malware detection and anti-crimeware provider, advised that Microsoft Security Automatic Updates be enabled and that up-to-date anti-malware software be used.

"The combination of these two will ensure the best protection possible," Debolt said.

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:
microsoftpatchsecurityvulnerabilities

Related Articles

  • Marathon OAIC investigation finds Optus breached 51,000 customers' privacy Marathon OAIC investigation finds Optus breached 51,000 customers' privacy
  • US gov shortens cyber fix window to three days US gov shortens cyber fix window to three days
  • Anthropic releases Mythos-class model for public use Anthropic releases Mythos-class model for public use
  • Apple bumps up security in fresh operating system releases Apple bumps up security in fresh operating system releases
Join our WhatsApp Channel

Partner Content

From test case to control tower: How DXC and ServiceNow are governing enterprise AI at scale
Promoted Content From test case to control tower: How DXC and ServiceNow are governing enterprise AI at scale
Intelligence × Trust: the equation that will decide Australia's AI winners
Promoted Content Intelligence × Trust: the equation that will decide Australia's AI winners
Take control of your connectivity with Telstra’s Adaptive Networks Centre
Partner Content Take control of your connectivity with Telstra’s Adaptive Networks Centre
Agile isn’t the problem: why projects still fail, and what’s missing
Partner Content Agile isn’t the problem: why projects still fail, and what’s missing

Sponsored Whitepapers

When cyber risk has no clear owner: A practical guide for senior Australian business leaders
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
High-volume data sources for AI-driven security analytics
High-volume data sources for AI-driven security analytics
How healthcare organisations can get more value from cloud
How healthcare organisations can get more value from cloud

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • Forrester's AI Forum Sydney Forrester's AI Forum Sydney
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

Defence says Palantir is "sandboxed" in its environment

Defence says Palantir is "sandboxed" in its environment

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Researchers build self-replicating AI worm with BYO LLM

Researchers build self-replicating AI worm with BYO LLM

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.