Risk
1/7/2013
09:24 AM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Microsoft Patches Won't Fix IE Zero-Day Vulnerability

Microsoft's first Patch Tuesday of 2013 will address 12 flaws, including a critical vulnerability affecting virtually all Windows machines.

CES 2013: 9 Cool Gadgets
CES 2013: 9 Cool Gadgets
(click image for larger view and for slideshow)
For many tech professionals, Tuesday will be all about the Consumer Electronics Show (CES) spectacle. For IT admins, though, the day is likely to be spent deploying Microsoft's first security patches of 2013. The collection of seven patches will address 12 problems, two of which have been classified as critical vulnerabilities. It won't, however, offer a permanent solution for an Internet Explorer (IE) vulnerability discovered in late December.

Both of the critical vulnerabilities Microsoft will patch allow attackers to remotely execute code on unpatched machines. One affects only Windows 7 and Windows Server 2008 R2 -- but the confined risk doesn't mitigate the potential damage, given that Windows 7 is the world's most widely deployed OS. The other involves virtually all Windows variations currently used in the enterprise: Windows XP through Windows 8, as well as Windows Server 2003, 2008, 2008 R2 and 2012. Instituting the patches could cause admins a few minor headaches; all but one of the seven patches, including the two most urgent ones, require that machines be restarted.

The presently unpatched zero-day vulnerability in IE, meanwhile, was first described by cybersecurity firm FireEye, which published a blog post on December 28, one day after receiving reports that the website for the Council on Foreign Relations had been compromised. FireEye said the site had been injected with malicious code due to an error in IE 8. The firm declined to provide in-depth technical details until Microsoft issues a solution, but it noted that the JavaScript involved includes a few peculiarities, such as exploiting only browsers whose OS language is English, Chinese, Japanese, Korean or Russian.

Microsoft acknowledged the problem a day later and revealed that IE 6, 7 and 8 are affected. The company explained that an attacker "could take complete control of an affected system" and has offered a workaround until a complete patch is released.

[ Microsoft had a tough year in 2012, with disappointing sales for long-awaited products including Windows 8 and the Surface tablet. Learn 6 Things Microsoft Must Do In 2013. ]

Given how recently the exploit was discovered, it would have been surprising if Microsoft had bundled a patch into the forthcoming updates. The fact the IE 9 and 10 are not vulnerable takes a bit of the urgency off, but security firm Exodus Intelligence claims that the current workaround is easily subverted. The company provided technical details of the bypass to its customers, but will not make the information public until Microsoft has issued a patch.

In an earlier analysis, Exodus Intelligence co-founder Peter Vreugdenhil wrote that the vulnerability is "just another Internet Explorer use-after-free bug which was actually relatively easy to analyze and exploit." A Sophos Security blog post, meanwhile, took a more somewhat more aggressive tone in describing the risk, tracing the exploit to a handful of additional attacks and recommending that users avoid affected versions of IE.

In an email, IDC analyst Al Hilwa wrote that, "Releasing information about a vulnerability before it is patched is always a balancing act." If Microsoft learned that the exploit had become known within the hacker community, he asserted, the knowledge would compelled the the company's leaders to "exposite it and give recommendations even prior to figuring out a solution."

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
johnitguru
50%
50%
johnitguru,
User Rank: Apprentice
1/7/2013 | 6:22:35 PM
re: Microsoft Patches Won't Fix IE Zero-Day Vulnerability
I got tired of Microsoft viruses, scams and malware so I installed a really cool 3D Linux operating system for only $39.95 that is 100% compatible with all my Windows data and is 10 times faster called Robolinux.

It took me only 5 minutes to install it.

Now I can surf the web until I am blue in the face and I can't get a virus.

Check it out go to robolinux.org

http://robolinux.org
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-7877
Published: 2014-10-30
Unspecified vulnerability in the kernel in HP HP-UX B.11.31 allows local users to cause a denial of service via unknown vectors.

CVE-2014-3051
Published: 2014-10-29
The Internet Service Monitor (ISM) agent in IBM Tivoli Composite Application Manager (ITCAM) for Transactions 7.1 and 7.2 before 7.2.0.3 IF28, 7.3 before 7.3.0.1 IF30, and 7.4 before 7.4.0.0 IF18 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof s...

CVE-2014-3668
Published: 2014-10-29
Buffer overflow in the date_from_ISO8601 function in the mkgmtime implementation in libxmlrpc/xmlrpc.c in the XMLRPC extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) via (1) a crafted first argument t...

CVE-2014-3669
Published: 2014-10-29
Integer overflow in the object_custom function in ext/standard/var_unserializer.c in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an argument to the unserialize function ...

CVE-2014-3670
Published: 2014-10-29
The exif_ifd_make_value function in exif.c in the EXIF extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 operates on floating-point arrays incorrectly, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly exec...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.