Welcome | Sign In
LinuxInsider.com
Security

Patch Tuesday Fixes 10 Vulnerabilities

Print Version
E-Mail Article
Reprints
Patch Tuesday Fixes 10 Vulnerabilities

"Despite having a dedicated day to focus on Microsoft patches, network administrators are still faced with a double whammy," said Mitchell Ashley, CTO and vice president of customer experience at StillSecure. "The window of time from when patches are released to when an exploit is readily available is rapidly shrinking."


Increase Customer Sales with VerticalResponse Email Marketing! Quickly and easily send email newsletters, coupons & sales announcements to your customers – no technical expertise needed. Sign up for your Free Trial today and send 100 emails on us!

Microsoft's (Nasdaq: MSFT) Patch Tuesday issued a slew of fixes in its April release, most of which focused on browser flaws. The software giant's monthly security update issued five patches in all, including three "critical," one "moderate" and one "important" patch.

Ten vulnerabilities in all were addressed in the cumulative fix. Of special note, this month's patch includes a remedy for the highly publicized "createTextRange()" flaw, along with fixes for HTML parsing errors, script executions and address bar spoofing issues.

These flaws could result in a remote code execution risk, allowing a hacker to take control of a victim's computer, according to Microsoft, though an attacker would have to create a malicious Web site and entice people to visit it in order to gain access to the PC.

Hackers Plan Ahead

Thanks to the schedule Microsoft has provided the market through Patch Tuesday, network administrators are able to more effectively plan their patching cycles, said Mitchell Ashley, CTO and vice president of customer experience at StillSecure. Unfortunately, he added, hackers can more effectively plan their attacks as well.

"Despite having a dedicated day to focus on Microsoft patches, network administrators are still faced with a double whammy," Ashley told TechNewsWorld. "The window of time from when patches are released to when an exploit is readily available is rapidly shrinking. Plus, networks are growing more complex with new kinds of devices like PDAs so more time is required to manage the vulnerability and patching processes."

Vulnerabilities Exploited

The createTextRange() flaw caused a stir in late March. Rated extremely critical, the flaw had the potential to impact thousands of users because it applied to frequently used radio buttons. A radio button is a form field that presents the user with a selection that can be chosen by clicking on a button.

Malware writers were exploiting the vulnerability to put spyware and other malicious code on victims' PCs before Microsoft issued a patch. Security firm eEye Digital Security said its temporary fix was downloaded by 156,000 customers from the time it was discovered until Microsoft issued its own fix. The IE update covers all versions of the operating system.

Microsoft said only the createTextRange() flaw was exploited, but Symantec (Nasdaq: SYMC) reported that three of the flaws were being exploited before Microsoft released its patch. Security researchers expect additional attacks to follow.

Beyond IE

Microsoft also issued critical updates for a flaw in the execution of the RDS.Dataspace ActiveX control and for a vulnerability in Windows Explorer's handling of COM objects. Attackers could make Explorer fail by visiting a specially designed site. All versions of Windows are affected by these critical flaws.

Other fixes in this patch cycle include an "important" update that addresses issues with how Outlook 5.5 and 6 handle Windows Address Book files. This vulnerability would allow an attacker to install programs, view, change or delete data, or create new accounts with full user rights, Microsoft said in its advisory.

An important update was also issued for FrontPage Server Extensions. A flaw within the technology could allow for cross-site scripting, Microsoft said.

Taking Accurate Inventory

Planning a network-wide restart requires extra scheduling on behalf of the IT staff, increasing the pressure to secure the network in a timely manner without any business disruptions, Ashley noted.

"One suggestion for decreasing these time-to-patch sensitivities is to take an accurate inventory of the devices on the network, who is using them, and what systems they are running prior to Patch Tuesday's announcement," Ashley said. "Another is to deploy multiple layers of security including intrusion detection and prevention (IDS/IPS), vulnerability management, and network access control, in case devices were overlooked or a security update was missed."


Print Version E-Mail Article Reprints More by Jennifer LeClaire


More by Jennifer LeClaire

The Digital Car: Cool Automotive Accessories, Part 2
January 16, 2007
Not all the latest high-tech automotive electronics are built to entertain. Many give the driver more information and more control. Vehicle tracking devices can tell where the car is at any time, software installed in a smartphone can turn off a vehicle's security system whenever the owner approaches, and diagnostic tools can tell what's wrong with the engine -- and how much it'll be to fix it.
'World of Warcraft' Wows 8 Million Subscribers
January 12, 2007
"World of Warcraft," the massively multiplayer online role-playing game, has reached the 8 million subscriber mark. Since debuting in North America in Nov. 2004, "World of Warcraft" has become the most popular MMORPG in the world. The franchise is available in seven different languages and is played on at least four continents.
AT&T Bids Goodbye to Cingular Brand
January 12, 2007
Starting Monday, AT&T will launch a multimedia campaign to transition the Cingular Wireless brand name into its advertising and customer communications. The campaign will integrate popular imagery, phrases and icons from Cingular's traditional advertising, including the "raising the bar" tagline, the "Jack" character and the color orange.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network