03:48 PM
Connect Directly

Microsoft Releases Mammoth Security Patch

The company's 13 security bulletins set a record and bring Windows 7 its first official fixes.

Microsoft on Tuesday issued 13 security bulletins covering 34 vulnerabilities as part of its regularly scheduled monthly patch cycle.

Acknowledging that this represents the most security bulletins the company has ever released, Microsoft senior security program manager Jerry Bryant played down the size issue by noting that the company has released between 10 and 12 bulletins before so "this is business as usual."

In June, the company set a record of 31 for the number of vulnerabilities fixed, not to be confused with the number of bulletins released, which was 10 that month.

This month's bounty of fixes affects Windows, Internet Explorer, Silverlight, Microsoft Office, Developer Tools, Forefront and SQL Server.

The update also resolves two security advisories about vulnerabilities in Microsoft Server Message Block version 2 (SMBv2) and the File Transfer Protocol (FTP) Service in Microsoft Internet Information Services (IIS).

Eight of the 13 bulletins are rated "critical." Six of those get a one on Microsoft's Exploitability Index, which is why the company advises patching them immediately.

Ben Greenbaum, senior research manager, Symantec Security Response, points to MS09-054 and MS09-062 as particularly serious.

"The primary danger the GDI+ graphics library and Internet Explorer vulnerabilities pose is that these vulnerable components are present on the majority of Windows machines," he said in an e-mailed statement. "Many of the issues addressed today are fairly trivial to exploit. For example, via a drive-by-download style attack. In that case, all a computer user would have to do to become infected by an attack using one of these vulnerabilities is unsuspectingly visit a compromised Web site."

Of the five bulletins that affect Windows 7, two -- MS09-054 and MS09-061 -- are designated "critical."

Sheldon Malm, senior director of security strategy at Rapid7, said in an e-mail that MS09-056, a flaw in the Windows CryptoAPI that could allow spoofing, is the most interesting vulnerability because of its connection to trusted Security services, even if it's not among those that need to be immediately addressed.

The flaw was used earlier this month to create a certificate, which was distributed to a security mailing list, that could have allowed a Web site to impersonate PayPal's Web site.

Qualys CTO Wolfgang Kandek said in an e-mail, "The vulnerability is rated only as 'important' because it does not allow the attacker to take over the machine, but it can be used to steal the user's credentials to any Web site."

InformationWeek has published an in-depth report on smartphone security. Download the report here (registration required).

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2015-04-24
Multiple cross-site request forgery (CSRF) vulnerabilities in Zen Cart 1.3.9h allow remote attackers to hijack the authentication of administrators for requests that (1) delete a product via a delete_product_confirm action to product.php or (2) disable a product via a setflag action to categories.ph...

Published: 2015-04-24
Multiple cross-site request forgery (CSRF) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to hijack the authentication of administrators for requests that (1) add a user via an adduser action to admin/index.php or (2) conduct static PHP code injection attacks in .htusers...

Published: 2015-04-24
Multiple cross-site scripting (XSS) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to inject arbitrary web script or HTML via the (1) selitems[] parameter in a copy, (2) chmod, or (3) arch action to admin/index.php or (4) searchitem parameter in a search action to admin/...

Published: 2015-04-24
Multiple stack-based buffer overflows in HttpUtils.dll in TVMOBiLi before allow remote attackers to cause a denial of service (tvMobiliService service crash) via a long string in a (1) GET or (2) HEAD request to TCP port 30888.

Published: 2015-04-24
Red Hat JBoss Operations Network 3.3.1 does not properly restrict access to certain APIs, which allows remote attackers to execute arbitrary Java methos via the (1) ServerInvokerServlet or (2) SchedulerService or (3) cause a denial of service (disk consumption) via the ContentManager.

Dark Reading Radio
Archived Dark Reading Radio
Join security and risk expert John Pironti and Dark Reading Editor-in-Chief Tim Wilson for a live online discussion of the sea-changing shift in security strategy and the many ways it is affecting IT and business.