Risk
7/9/2013
09:09 AM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Microsoft Patch Tuesday Fixes Six Critical Bugs

Microsoft issues patches for an unusual number of critical vulnerabilities that encompass the company's entire software ecosystem.

10 Hidden Benefits of Windows 8.1
10 Hidden Benefits of Windows 8.1
(click image for larger view)
Microsoft has been focusing on Windows 8 lately, but there are numerous versions of Windows in use and the company can't ignore them. On Tuesday, Microsoft will release an unusually high number of critical patches for almost all of them.

July's Patch Tuesday includes fixes for six critical flaws, all of which involve remote execution bugs that could allow attackers to take control of a user's machine. The affected platforms and software includes not only all currently-supported versions of Windows, but also all Internet Explorer versions from IE 6 onward, as well as Office, Lync, Visual Studio, Silverlightand Microsoft's .NET framework. If you use any Microsoft product from the last several years, in other words, you probably need at least some of the patches.

Two of the critical exploits require that machines be restarted. Some versions of Windows are more vulnerable than others without a given patch, meaning that some of the updates designated as "critical" overall are downgraded for specific platforms. Nonetheless, all versions of Windows are afflicted by multiple high-priority exploits.

[ Microsoft is moving more quickly to fix problems. Read Microsoft Releases First Windows 8.1 Fixes. ]

Microsoft has also prepared a seventh patch, which it classified as "important." It addresses a vulnerability in Windows Defender, the platform's pre-installed security software.

The large batch of critical fixes has raised eyebrows in the security community. In a blog post, Paul Ducklin, head of technology at security vendor Sophos, advised businesses to get their "operational ducks in a row," adding that the patches are unusually broad. Windows Server Core, for example, is usually excluded from Patch Tuesdays because its stripped-down feature set offers a "significantly reduced attack surface area." It's therefore notable that July's updates include a Windows Server Core 2012 reboot, Ducklin wrote.

Paul Henry, a security and forensic analyst at security tools firm Lumension, similarly told The Guardian that this month's patches constitute "one of the uglier releases we've seen from Microsoft this year." Graham Cluley, a senior technology consultant with Sophos, channeled the hacker vernacular to describe the threat, warning in a blog post to "patch before you're pwned."

IT managers, in short, should be on alert.

The updates are expected to address a somewhat controversial exploit reported in June by Google researcher Tavis Ormandy. Ormandy discovered a zero-day vulnerability linked to the kernel for all editions of Windows from Windows 2000 to the present. The Google researcher, who had previously criticized Microsoft as "difficult to work with" reported the bug privately but waited only a few days before publishing his findings online.

Some security professionals have cried foul, arguing that Ormandy's public disclosure was unethical because it left Microsoft too little time to develop a fix and, in effect, gave malware authors a dangerous head start.

Security firm Secunia determined that the bug is only semi-urgent. Still, the firm noted that attackers could use the vulnerability to gain escalated privileges, or to hijack a machine for a denial-of-service attack. Tod Beardsley, a security researcher with Metasploit, noted in a blog, however, that this sort of local exploit provides a foundation for more damaging attacks.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-4231
Published: 2015-07-03
The Python interpreter in Cisco NX-OS 6.2(8a) on Nexus 7000 devices allows local users to bypass intended access restrictions and delete an arbitrary VDC's files by leveraging administrative privileges in one VDC, aka Bug ID CSCur08416.

CVE-2015-4232
Published: 2015-07-03
Cisco NX-OS 6.2(10) on Nexus and MDS 9000 devices allows local users to execute arbitrary OS commands by entering crafted tar parameters in the CLI, aka Bug ID CSCus44856.

CVE-2015-4234
Published: 2015-07-03
Cisco NX-OS 6.0(2) and 6.2(2) on Nexus devices has an improper OS configuration, which allows local users to obtain root access via unspecified input to the Python interpreter, aka Bug IDs CSCun02887, CSCur00115, and CSCur00127.

CVE-2015-4237
Published: 2015-07-03
The CLI parser in Cisco NX-OS 4.1(2)E1(1), 6.2(11b), 6.2(12), 7.2(0)ZZ(99.1), 7.2(0)ZZ(99.3), and 9.1(1)SV1(3.1.8) on Nexus devices allows local users to execute arbitrary OS commands via crafted characters in a filename, aka Bug IDs CSCuv08491, CSCuv08443, CSCuv08480, CSCuv08448, CSCuu99291, CSCuv0...

CVE-2015-4239
Published: 2015-07-03
Cisco Adaptive Security Appliance (ASA) Software 9.3(2.243) and 100.13(0.21) allows remote attackers to cause a denial of service (device reload) by sending crafted OSPFv2 packets on the local network, aka Bug ID CSCus84220.

Dark Reading Radio
Archived Dark Reading Radio
Marc Spitler, co-author of the Verizon DBIR will share some of the lesser-known but most intriguing tidbits from the massive report