You are here: silicon.com > Software > Security Strategy

Security Strategy

Microsoft: Another busy Patch Tuesday

Windows and Office flaws...

Tags: patch tuesday, flaws, flaw, microsoft

By Joris Evers

Published: 9 August 2006 09:15 BST

As part of its monthly security update cycle, Microsoft on Tuesday released a dozen security bulletins. Nine of them are tagged critical, the company's highest severity rating. The alerts give details of 20 flaws in Windows and three in Office, all of which Microsoft has now fixed.

Several of the issues, such as a vulnerability in PowerPoint, have already been publicly reported and are being actively used in cyber attacks. However, the bundle of updates also covers bugs Microsoft discovered itself, the company said. These issues have not been publicly disclosed and are not described in the bulletins.

Monty Ijzerman, a senior manager at McAfee's Avert Labs, said in a statement: "Today, Microsoft patched 23 vulnerabilities, the highest number since their monthly patch programme started." Of those flaws, 11 were publicly known or exploited before Microsoft provided fixes, he said.

Of specific interest is a remotely exploitable vulnerability in Windows, which Microsoft reports is already being used in attacks on PCs. The problem lies in a Windows service that provides support for networking features such as file sharing and printer sharing, the company said in security bulletin MS06-040.

Christopher Budd, security programme manager at Microsoft, said in an interview: "This is the one that we're encouraging people to prioritise and put on the top of the stack for their testing and deployment." If immediate patching is not possible, Microsoft suggests using its workarounds, he said.

The flaw addressed in MS06-040 is the only one in Microsoft's Tuesday patch bunch that could let an anonymous attacker remotely commandeer a Windows PC without any user interaction, Budd said. Microsoft has seen a "very limited attack" that already exploited this flaw, he added.

The infamous MSBlast worm, which wreaked havoc in 2003, exploited a similar flaw, related to a Windows component called remote procedure call.

Last month, Microsoft patched a potential Windows worm hole when it released seven bulletins tackling 18 security flaws in Windows and Office. The patching rush started in June, when it released 12 bulletins. It came after a patch lull, with only three alerts in May, five in April and two in March.

Another of this month's flaws that could be exploited without any user interaction lies in the Windows Domain Name System (DNS) client, which is used to help translate URLs into numerical IP addresses. However, an attacker has to be on the same sub-network as the intended target or must trick the user into making a DNS request to a malicious server, Microsoft said in bulletin MS06-041.

The bulk of the problems addressed by the August patches could be used for attacks via the web or email. They include security holes in the Internet Explorer web browser, the Outlook Express email client and other Windows and Office components.

For example, MS06-042 delivers fixes for eight IE bugs, and the user has to be duped into visiting a malicious website for attacks based on the holes to succeed, Microsoft said.

While it is a busy Patch Tuesday, Microsoft has not addressed all known flaws in its products. For example, a variant of a bug patched last month in a Windows component called "mailslot" is still without a fix. Proof-of-concept code that exploits this flaw was posted to the net last month.

Microsoft recommends people install the critical fixes immediately. The updates are available via the Windows Update and Automatic Updates tools. Temporary workarounds are outlined in the security bulletins for those who can't immediately apply the patches.

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Junior .NET Developer / QA - London - .NET / QA - Junior .NET Developer

Duties required of the Junior .NET Developer / QA: - Review on a daily basis (and at busy times, several times a day) the outstanding assigned bug ...

Business Analyst ( OO , Java ) - London

Primary Responsibilities - Work with Financial Engineers and Developers to conduct sophisticated validation of existing and new models; develop test ...

Transmission/Component Design Engineer, Contract, East Midlands

Leading Automotive Tier 1 company based in the East Midlands require a Design Engineer on a contract basis. The idea candidate will have experience ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: