RT @Droid_News: Motorola earnings beat expectations http://bit.ly/btsNAg | #Droid #Android
26 minutes ago by frogiss117 on twitterZDNet is available in the following editions:
Patch Tuesday update addresses vulnerabilities in DirectShow, SMB Protocol, ActiveX, Windows Shell Handler, and 32-bit Windows.
microsoft office, attack, small and medium business, vulnerability, computer, attacker, server, microsoft, microsoft windows, 32-bit
Microsoft fixed 26 vulnerabilities in 13 security bulletins as part of its Patch Tuesday, including critical ones for Windows that could be exploited to take control of a computer and one that has resided in the 32-bit Windows kernel since its release 17 years ago.
The top priorities for deployment are bulletins plugging holes in the SMB (Server Message Block) Protocol, Windows Shell Handler, ActiveX via Internet Explorer, DirectShow, and the 32-bit version of Windows, Jerry Bryant, a lead senior security communications manager at Microsoft, wrote in a blog post.
The DirectShow bulletin should be at the top of the list, according to Bryant. It is critical for all supported versions of Windows except Itanium-based server products. To exploit the hole, an attacker could host a malicious AVI (Audio Video Interleave) file on a Web site, and lure a user to visit the site or send the file via e-mail so the user could open it.
In the SMB bulletin, critical for all versions of Windows except Vista and Server 2008, an attacker would need to host a malicious server and convince a client system to connect to it, or an attacker could try to perform a man-in-the-middle attack by responding to SMB requests from clients, Bryant said.
In the critical Windows Shell Handler vulnerability, which affects Windows 2000, XP, and Server 2003, an attack could come via a specially crafted link that appears to be valid to the ShellExecute API (application programming interface).
The cumulative update for ActiveX Killbits is critical, but a Killbit does not address the underlying vulnerability. It is a registry setting that keeps the vulnerable ActiveX control from running in IE.
The vulnerability affecting the 32-bit Windows kernel, which Microsoft announced last month, after Google engineer Tavis Ormandy disclosed it on a security e-mail list, could allow an attacker to elevate privileges to full system access, once the attacker is already in the system.
Much has been made of the fact that the hole is 17 years old, but Ormandy said he informed Microsoft about it in June 2009. "You can criticize them for taking a long time to fix a bug", but not if they didn't know about it, said Pedram Amini, who runs the Zero Day Initiative.
Microsoft is aware of publicly available proof-of-concept code for that issue, but is not aware of any active attacks at this time, Bryant wrote.
The most important bug for IT security teams is the one affecting DirectShow, said Andrew Storm, director of security compliance at security firm nCircle. "The nature of the exploit lends itself to drive-by attacks that leave unsuspecting victims infected," he said. "Since media is what excites people most on the Internet today, an exploit of this bug would make it extremely easy to entice users to watch videos that are actually gateways to malware."
Meanwhile, the Shell Handler vulnerability has the potential for an unlimited amount of damage, which should make potential attackers take notice, he said.
This month's "sleeper update" is probably a hole in Windows TCP/IP (Transmission Control Protocol-Internet Protocol) that could allow remote code execution if specially crafted packets were sent to a computer with IPv6 enabled, said HD Moore, chief security officer of Rapid7. "While it has an exploitability rating of 2 based on the requirement for an attacker to be on-link to the target host, Wi-Fi access points provide link level connectivity to target systems" he said. "Customers should not confuse the exploitability index with exposure severity--the priority of this patch should be raised where mobile users are prevalent."
Two bulletins, both rated "important", affect older versions of Microsoft Office and could allow an attacker to remotely execute code on the computer via a hole in PowerPoint or via a specially crafted Office file.
The bulletins affect Windows 2000, XP, Vista, and Windows 7, as well as Server 2003 and 2008, Office XP, Office 2003, and Office 2004 for Mac, according to the advisory.
Microsoft also issued a security advisory to provide a work-around for a publicly known hole in the Transport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols.
And Microsoft updated its Malicious Software Removal Tool to include the Win32/Pushbot, a worm that spreads via MSN Messenger and AIM, and opens a backdoor so an attacker can take complete control of the machine.
Microsoft is still working on patches for a hole disclosed last week in Internet Explorer that could lead to data leakage and an SMB hole that was disclosed in November.
"The [SMB] issue cannot be used to allow an attacker to take control of a system remotely, but instead can result in a system becoming unresponsive due to resource consumption," Microsoft said in a statement. "At this time, Microsoft is not aware of any attacks using this vulnerability."
This article was first published as a blog post on CNET News.
RT @Droid_News: Motorola earnings beat expectations http://bit.ly/btsNAg | #Droid #Android
26 minutes ago by frogiss117 on twitterUS court rejects class action status for Intel antitrust suit http://bit.ly/cWeSQZ
31 minutes ago by MeetAnnMCarron on twitterUS court rejects class action status for Intel antitrust suit http://bit.ly/9mqiJR
31 minutes ago by lifesystem1 on twitterhttp://bit.ly/8v7Ov3 US court rejects class action status for Intel antitrust suit - ZDNet Asia http://is.gd/dSz7R
33 minutes ago by easytweeting on topsyUS court rejects class action status for Intel antitrust suit http://bit.ly/9AbnMF
46 minutes ago by MLMRocketFuel on twitterNon-green IT products 'marketing suicide': This 50-hectare eco-business park is described as a "living laboratory"... http://bit.ly/aCqko4
50 minutes ago by greenexistence on twittergreat! US court rejects class action status for Intel antitrust suit http://bit.ly/9acwER Good day!
51 minutes ago by bestwinnernet on twitterShocked! RT: @danielgoh: Oh really? RT @scoopsg: (zdnetasia) S'pore marketeers not chirping to Twitter's tune http://scoo.ps/dpkySs
54 minutes ago by mitchtan on twitterNon-green IT products 'marketing suicide': By Munir Kotadia, ZDNet Australia on July 30, 2010 (8 minutes ago) Vend... http://bit.ly/aCqko4
1 hour 5 minutes ago by OutsourceMethod on twittersg marketeers not chirping to twitter's tune http://bit.ly/aRAa1Y - baby steps baby steps
1 hour 18 minutes ago by sashizoso on twitterNon-green IT products 'marketing suicide': This 50-hectare eco-business park is described as a "living laboratory"... http://bit.ly/cEkDUD
1 hour 18 minutes ago by BlissfulSeed on twitterNon-green IT products 'marketing suicide': At the same time, it seems vendors see green technology as a very high ... http://bit.ly/aCqko4
1 hour 33 minutes ago by greentreats on topsyOh really? RT @scoopsg: (zdnetasia) S'pore marketeers not chirping to Twitter's tune http://scoo.ps/dpkySs
1 hour 46 minutes ago by danielgoh on twitter@mrcolinlim but of course for more tech updates you can always visit zdnetasia.com
2 hours 11 minutes ago by t_phuck on twitterRT @zdnetasia: Searchable Facebook user data posted to Pirate Bay http://bit.ly/ciJQxY
2 hours 30 minutes ago by phyllis777loves on topsyin the mean time, if you need to find PDF eBooks, you may use http://www.findpdf.us/
5 hours 9 minutes ago by findpdf on Researchers find workaround for Adobe PDF fixJust want to say what a great blog you got here! My appreciation of your work, cause i am an IT student also. Try this one too, http://w...
5 hours 17 minutes ago by winsource on Making the case for Filipino IT entrepreneurshipHi, We have ton of HP empty cartridges. Could you collect them in our office??
Thanks
Thanks Kenneth, for your insights. Good to know people out there can see the issue for what it is, and to do so impassively, that is. ...
2 days 15 minutes ago by yedwin on iPhone 4 shows prudence in procrastinationWhile I agree that the issues with the device have raised many an eyebrow, I think it's unwise to forget that many phone reviews have...
2 days 27 minutes ago by kennethkoh on iPhone 4 shows prudence in procrastinationThe online apple store http://store.apple.com/ is not available now. Maybe it's updating the pricing ;)
2 days 25 minutes ago by mingnow on iPhone 4 to ring in Singapore on FridayAfter an awful silence, finally the prices are out..
3 days 20 minutes ago by melvinchia on iPhone 4 to ring in Singapore on FridayGlad you discovered the Xfce 4.6 magic. Its other endearing feature is its phenomenal configurability. You can make the desktop look and ...
3 days 27 minutes ago by gnome_refugee on Smitten with Xfce 4yep, tried them all and xfce with compiz/emerald instead of fvwm is by far the best experience I've had. If you didn't know ther...
3 days 25 minutes ago by ggolemg on Smitten with Xfce 4@mingnow: why do you think so? How do you think the FOSS community could tackle this issue? I'm involved in a lot of efforts to get t...
3 days 31 minutes ago by fredericmuller on Taobao initiates Chinese open source revolutionGeez. I would think giving free books and getting kids to school would be a better place to start.
3 days 39 minutes ago by mingnow on India's US$35 tablet--how low can it go?I think it's great the that country with the biggest internet population is finally contributing back to the open-source world. I thi...
4 days 25 minutes ago by mingnow on Taobao initiates Chinese open source revolutionhey.there Im Wendy from a PR Agency.I find your blog interesting and well written.In days to come,we would hold an event. Therefore We ...
4 days 56 minutes ago by wendy on iPhone 4 shows prudence in procrastinationIt could be done without all these. Just use the opacity addon of Compiz.
4 days 20 minutes ago by hariks0 on How to get RGBA support in UbuntuStop Waiting Start Switching to Juniper
Free Gartner Report shows it reduces costs and increases efficiency
What makes a hospital a smart hospital?
Download your copy of 'The Smart Hospital' Resource Kit to learn more
2010 IT Salary & Skills Report
Find out the salary range of IT professionals. Join activeTechPros for free access to the report.