Top Tech News

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
News & Product Reviews for Tech Leaders
Friday, November 20th 
Home
Network Security
Microsoft/Windows
Linux/Open Source
Apple/Macintosh
Wireless Tech
World Wide Web
Tech Trends
Data Storage
Software
Hardware
Communications
Spam & Hackers
Chips & Processors
E-Business
Personal Tech
 
Free Newsletters
Top CIO News
 
Mobile Tech Today
 

Advertisement
Microsoft/Windows

Researchers Rate All Six Microsoft Patches as Critical

Researchers Rate All Six Microsoft Patches as Critical
July 15, 2009 8:57AM

Bookmark and Share
Microsoft rated three of six Patch Tuesday issues as critical, but security researchers say the other three can quickly escalate. Wolfgang Kandek of Qualys said the ISA, Publisher and virtualization vulnerabilities can give a remote attacker control of a computer. Andrew Storms of nCircle hopes for a more complete ActiveX patch later.


Microsoft Relevant Products/Services on Tuesday released six bulletins as part of its monthly patch cycle. Three of the bulletins cover critical flaws, including two unpatched zero-day vulnerabilities. Three other bulletins address important risks that security Relevant Products/Services researchers said can quickly escalate to critical.

Wolfgang Kandek, CTO of Qualys, said Microsoft's advisories should be addressed immediately because they allow an attacker to take complete control of a victim's computer.

Microsoft proxy server Relevant Products/Services ISA 2006 has a vulnerability rated as important that allows remote unauthenticated users to access the server. However, paired with a knowledge of the administrator's username, attackers can take full control of the server. Because administrator usernames are often easy to guess, Kandek said, this vulnerability deserves special attention if IT Relevant Products/Services organizations are using ISA with the Radius configuration.

Likewise, MS09-030 is an advisory for the Publisher component in the MS Office 2007 suite rated as important, but can be used to take full control of a system if the victim is logged in as administrator. If an organization uses Publisher or has it installed as part of Office 2007, this should be treated as critical as well, Kandek said.

"Microsoft also provided patches for their virtualization Relevant Products/Services product VPC and Virtual Server on all versions (MS09-033) preventing an elevation of privilege in the guest operating system. This is classified as important because local access to the guest OS is required," Kandek said. "This bulletin is interesting because this vulnerability is introduced by the fact that the OS is running under a virtual environment and allows the user access to privileged kernel mode."

True ActiveX Fix Coming

Andrew Storms, director of security operations for nCircle, isn't surprised that Microsoft released updates that address two of three critical zero-day exploits this month. He also anticipates a more complete patch for ActiveX later, since Tuesday's update only issues killbits on ActiveX controls in Internet Explorer.

Essentially, Microsoft opted to disable functionality with the MS09_0032 security bulletin, but hasn't fixed the underlying vulnerability. That means if an attacker can manage to convince a user to revert the killbits, then the machine is once again vulnerable.

"Generally, newer Microsoft products have been more secure Relevant Products/Services than older products. Either they are not affected by vulnerabilities or have lower severity ratings. However, this month we have two bulletins that buck the trend," Storms said. "MS09-029 lists the vulnerability as critical for all operating systems -- even the newer Vista and Server 2008. In the same vein, MS09-030 affects only the newest version of Microsoft Office Publisher. While having these two bugs in new Microsoft products fixed in the same month may only be a coincidence, it is something to watch in coming months." (continued...)

1  |  2  |  Next Page >

Advertisement


 Microsoft/Windows
1. Ballmer Says Windows 7 Sales Good
2. Office 2010 Integrates with the Web
3. MS Told To Stop Some Windows Sales
4. Microsoft Releases Multiple Betas
5. IE9 Likely To Access PC Hardware


advertisement

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  Barnes & Noble Nook Is Delayed
  Ballmer Says Windows 7 Sales Good
  New Pogoplug 'Cloud' Gets Social
  Chrome OS Team Aims for Speed
  FAA Glitch Causes Air Travel Delays

 Technology Marketplace
Business Intelligence
IBM - Smarter business for a Smarter Planet.
 
Compliance
Webcast: SOX, GLBA, HIPAA Compliance and IT security controls.
 
Customer Service
Rackspace Hosting: 24x7x365 Support, Windows and Linux Certified
 
Data Security
Secure your data center today with the TippingPoint N-Platform
 
Enterprise Hardware
IT Costs out of Control? Download APC's FREE Cooling Efficiency kit.
 
Enterprise I.T.
Learn how Microsoft server upgrades can create efficiencies
Rackspace: It makes a difference when you focus on support
IBM - Smarter technology for a Smarter Planet.
Simplify. Automate. Innovate. The new network is here.
IT Costs out of Control? Download our FREE Cooling Efficiency kit.
Windows 7 Enterprise designed specifically for IT Professionals
 
Enterprise Software
Open cross-network software provides rich user experiences and fast time to market.
 
Innovation
3-D scaling lets networks support more subscribers, services & bandwidth -- at the same time.
 
Microsoft/Windows
Read about how to add efficiencies with Microsoft Virtualization.
Check out the new Windows 7 features. Download the FREE trial.
 
Network Security
Junos software platform and Juniper systems provide new cloud-networking & security solutions.
 
Security Products
Secure your data center today with TippingPoint's N-Platform
 
Navigation
Top Tech News
Home/Top News | Network Security | Microsoft/Windows | Linux/Open Source | Apple/Macintosh | Wireless Tech | World Wide Web
Tech Trends | Data Storage | Software | Hardware | Communications | Spam & Hackers | Chips & Processors
E-Business | Personal Tech
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2009 Top Tech News. All rights reserved. Article rating technology by Blogowogo.