Welcome | Sign In
TechNewsWorld.com
Security

Microsoft's Latest Patches Include First Vista Fix

Print Version
E-Mail Article
Reprints
Microsoft's Latest Patches Include First Vista Fix

Microsoft has issued a new set of patches for vulnerabilities affecting Internet Explorer and the Windows operating system, including the first one that is specific to Vista. "What this implies is that it is a flaw in the newer core, which was written under Microsoft's secured computing initiative," said Amol Sarwate, research manager of the vulnerability research lab at Qualys.


How Much is 'Free' Costing You?
Learn how DaveRamsey.com saw a 567% uplift in ROI with Omniture. This complimentary guide and webinar cover the most important factors in selecting an analytics solution. Download Now.

Microsoft (Nasdaq: MSFT) has released its latest batch of fixes in this month's Patch Tuesday announcement, employing a new format that makes it easier for IT administers to single out areas of risk, according to Amol Sarwate, research manager of the vulnerability research lab at Qualys.

The new format doesn't give users a total count of vulnerabilities, however. For instance, Sarwate told TechNewsWorld, one patch in this release fixes six different vulnerabilities in Internet Explorer -- a less-than-transparent accounting of the number of flaws the company is addressing.

Many of the newly uncovered vulnerabilities this time are variations on existing themes: flaws in Internet Explorer, for instance, or proof-of-concept vulnerabilities on which active development is occurring. Perhaps most worrisome -- and intriguing, according to at least one security researcher -- is a possible vector in SSL (Secure Sockets Layer), which is supposed to be the gold standard for Web site security.

Remote Execution

There are four patches rated "critical" that allow for remote execution, always a chief security concern.

Patches are essential for at least two -- MS07-031 and MS07-035 -- because they are in the core of the operating system, Sarwate said. "They do not require a browser to channel malware -- if a user has Windows, then he or she is vulnerable."

MS07-035, for instance, leaves users vulnerable when parsing HTML (Hypertext Markup Language) or text images. "Malicious content can execute in users' machines," Sarwate said.

MS07-033, for its part, distinguishes itself as having the largest number of flaws -- six in total -- that can leave Internet Explorer open to hack attacks.

Unpatched, MS07-033 can compromise a system if a user merely visits a corrupt Web site. "Another possibility is that a user could click on an ad that is corrupted -- in an otherwise safe Web site -- and become infected as well," Chad Harrington, chief technical evangelist at FireEye, told TechNewsWorld.

"Basically, when you launch your browser, MS07-033 can create an instant tunnel through a firewall," explained Roger Thompson, CTO of Exploit Prevention Labs.

"I expect this and 035 will be targeted by malware writers as soon as possible," he told TechNewsWorld.

What's the Problem With IE?

If it seems as though IE flaws are a recurring theme for Microsoft, that's because they are.

"In many ways, it is the same old, same old," Mark Loveless, security architect at Vernier Networks, told TechNewsWorld.

The good news is that Microsoft's reactive process works fairly well, which means it is less likely to issue a slew of code reds -- as it used to in the days when huge, well publicized worm attacks threatened the Internet on a regular basis.

Another dubious advantage of IE is that spammers are paying malware writers for their best worms and saving them for zero day exploits. "People aren't blowing their zero day exploits on goofy worms anymore," Loveless said. "Rather, they want the worms they do write to keep a low profile in order to remain on computers that much longer."

Another critical flaw, found in Microsoft's SSL channel, would allow a hacker to gain control or host a Web site that gives out "bad" security certificates, Sarwate said.

From a technical point of view, this is the most interesting flaw, according to Vernier Networks' Loveless. "It is interesting because there is only the potential for remote code execution, which means it would be hard to hack." The fact that it can be hacked at all is what makes it interesting, he explained.

It depends on the platform, FireEye's Harrington said, noting that the SSL flaw would be hard to remotely execute on Windows 2000 but not on Windows XP. "Of course, it is Windows XP that is much more commonly used."

That particular flaw is not found in the Vista version, he said.

Vista Issues

One moderate vulnerability in the release is specific to Vista, Sarwate said. There have been Vista vulnerabilities before, but they were also found in earlier versions of Windows. "This is the first time there is a vulnerability that only exists in Vista. What this implies is that it is a flaw in the newer core, which was written under Microsoft's secured computing initiative."

This flaw allows low-privileged users to access information that should only be accessed by the top-privileged users, he said.

Proof of Concept

One trend that is apparent in this latest group of patches, according to Dave Marcus, security research and communications manager at McAfee Avert Labs, is the that more malware writers are working on exploiting proof-of-concept flaws.

"Three or four of the new patches had pre-existing proof of concept," Marcus told TechNewsWorld. "We are seeing a lot more of that on a monthly basis -- and a lot quicker too, as more malware writers jump to exploit these vulnerabilities."


Print Version E-Mail Article Reprints More by Erika Morphy


More by Erika Morphy

Ballmer Gives Shareholders - and Dell - Cause for Optimism
November 20, 2009
Microsoft CEO Steve Ballmer was all smiles at the company's shareholders meeting, as he touted the early success of Windows 7. Ballmer's cheer may have been contagious; after posting a massive earnings decline for the third quarter, Dell needed some good news to latch onto, and the prospect of broad enterprise adoption of Windows 7 could spur PC sales.
AA.com Sucks the Fun Out of Trip-Planning
November 20, 2009
Using AA.com to book a flight was a painful experience. Densely packed, disorganized information was displayed in an unattractive format. On the plus side, it did seem as though the deals American Airlines advertised were real and not mere bait-and-switch lures. For anyone who wants a travel-planning Web site to inject a little pleasure into the experience, though, I say look elsewhere.
Salesforce.com Pumps Up Volume of Workplace Chatter
November 19, 2009
Salesforce.com has developed a collaboration platform that puts social networking to work. Salesforce Chatter facilitates employee collaboration on projects through Facebook-like profiles, status updates, feeds and groups. The question remains whether employees will be as open to social networking in the workplace as they are in their personal lives.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network