Latest Comments
"You should hire people to fight trojans and stuff"
by Me | Aug 29, 2008 7:27 AM
 
"Not exactly an innovative feature Microsoft. Other browsers have had this capability for a long ..."
by Chris Jones | Aug 28, 2008 7:38 PM
 
"Hey"
by Emilio Garcia | Aug 27, 2008 2:53 AM
 
"adfdas"
by ddd | Aug 26, 2008 4:24 PM
 
"i have seen a few iPhone porn sites and while most of them are crap I did run across one that ..."
by gate | Aug 23, 2008 6:30 AM

Microsoft releases 11 patches for 17 vulnerabilities: six critical

  • Email a Friend
  • Print Page
Microsoft releases 11 patches for 17 vulnerabilities: six critical
By Jim Carr
Feb 13, 2008 11:39 AM
Tags: "patch | management" | "microsoft's | patch | tuesday" | "february | patch | tuesday" | "microsoft | security"
Of the 17 – each of which can allow an attacker to take over a PC – six are client-side flaws. Four bugs impact Microsoft Office; two affect Internet Explorer (IE).

The release impacted a high number of Microsoft applications, including Active Directory, Active Directory Application Mode (ADAM), Internet Information Services (IIS), Visual Basic and Works.

However, what Microsoft didn't patch caught the eye of Jonathan Bitle, director of technical account management at Qualys.

"Microsoft has confirmed that a zero-day vulnerability is leveraging a weakness in Excel but they didn't release a patch for that issue," he told SCMagazineUS.com. "If they stick with the current patch cycle [and fix it on March 11], it will have been exploited for nearly two months."

Meanwhile, users should quickly apply bulletin MS08-010, which affects IE versions 6 and 7 across several versions of the Windows operating system, including Vista, Don Leatham, director of solutions and strategy at Lumension Security, told SCMagazineUS.com. This vulnerability impacts IE's HTML interpreter, a program “at the core of what a browser does," Leatham said.

"So anyone browsing outside the firewall could be vulnerable to exploits," he said. "It's very important that this one be looked at closely," he said.

Craig Schmugar, threat researcher at McAfee Avert Labs, said the patches “underline the need to be aware when opening files and the risk of surfing the web unprotected.”

"Many of the vulnerabilities addressed by the fixes could be exploited if a Windows user simply opens a file or visits a malicious or compromised website -favourite attack methods among cybercriminals,” he said.

However, Eric Schultze, chief technology officer at Shavlik Technologies, a patch-management vendor, said he would be concerned with the server-side bugs.

In the case of a client-side attack, "I would have to wait for someone to visit a website or open a document, so it's more difficult to target an attack against a company if I have to wait,” he said.

Schultze also noted that Microsoft didn't patch a previously announced vulnerability in VBScript/JScript.

"I'm guessing that they didn't like the results of some last-minute testing so they decided to hold it back to get it right," he said.

Microsoft was slated to release a dozen fixes, according to last week's advance notification advisory.

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
 
Patch Management Whitepapers