iTnews

Microsoft pulls ASLR DEP bypass patch

By Dan Kaplan on Aug 15, 2013 7:00AM
Microsoft pulls ASLR DEP bypass patch

Fix caused Exchange 2013 glitch.

Microsoft has pulled a patch released this week after it caused problems with Microsoft Exchange.

MS13-061 addressed three vulnerabilities in Exchange Server and was found to have triggered issues in version 2013, but not 2007 or 2010 environments.

"Specifically...the content index for mailbox databases shows as 'failed' and the Microsoft Exchange Search Host Controller service is renamed," Ross Smith IV, principal program manager of the Exchange Server product group said.

The three bugs lie in the way Exchange files are processed by Oracle Outside In, a set of libraries that software developers use to decode hundreds of file formats.

For administrators that already have deployed the patch, Microsoft recommends they apply KB 2879739, a workaround described here.

For those who have not yet installed the fix, the software giant suggests they don't and instead follow the steps listed in the "Workaround" section (under the "Vulnerability Information – Oracle Outside in Contains Multiple Exploitable Vulnerabilities") portion of the original security bulletin.

The patch also squashed a bypass in Address Space Layout Randomisation and Data Execution Prevention by removing all image pointers.

This article originally appeared at scmagazineus.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:
aslr dep exchange exploits microsoft patching security vulnerabilities

Partner Content

Resetting cyber security for the new threat landscape
Partner Content Resetting cyber security for the new threat landscape
Setting a path to self-funded mainframe-to-cloud modernisation with Micro Focus
Promoted Content Setting a path to self-funded mainframe-to-cloud modernisation with Micro Focus
New Intel NUCs advancing mini-PC possibilities for business
Partner Content New Intel NUCs advancing mini-PC possibilities for business
Tackling cybersecurity in 2021
Partner Content Tackling cybersecurity in 2021

Sponsored Whitepapers

Is the technology refresh dead?
Is the technology refresh dead?
DevSecOps: A framework for digital innovation
DevSecOps: A framework for digital innovation
Encryption: Protect your most critical data
Encryption: Protect your most critical data
Overcoming data security challenges in a hybrid, multicloud world
Overcoming data security challenges in a hybrid, multicloud world
Move beyond passwords
Move beyond passwords

Events

  • On-Demand Webinar: How Poly and Microsoft are Embracing Future Work Environments
  • [Webinar] - Transformation versus compliance – a guide for CXOs
  • Masters of Microsoft Licensing
By Dan Kaplan
Aug 15 2013
7:00AM
0 Comments

Related Articles

  • New Microsoft Exchange vulnerabilities require urgent patching: ACSC
  • The FBI remotely accessed private Exchange servers to remove web shells
  • White House taskforce meets over Microsoft software weaknesses
  • Microsoft tool provides automated Exchange threat mitigation
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Aussie Broadband to white label its services

Aussie Broadband to white label its services

Aussie Broadband says some customers are switching providers to get high-speed NBN discounts

Aussie Broadband says some customers are switching providers to get high-speed NBN discounts

ATO loses its cyber security chief

ATO loses its cyber security chief

Swinburne University data breach exposes details of 5000 staff, students

Swinburne University data breach exposes details of 5000 staff, students

You must be a registered member of iTnews to post a comment.
Log In | Register
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.