Risk
10/13/2009
03:48 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Microsoft Releases Mammoth Security Patch

The company's 13 security bulletins set a record and bring Windows 7 its first official fixes.

Microsoft on Tuesday issued 13 security bulletins covering 34 vulnerabilities as part of its regularly scheduled monthly patch cycle.

Acknowledging that this represents the most security bulletins the company has ever released, Microsoft senior security program manager Jerry Bryant played down the size issue by noting that the company has released between 10 and 12 bulletins before so "this is business as usual."

In June, the company set a record of 31 for the number of vulnerabilities fixed, not to be confused with the number of bulletins released, which was 10 that month.

This month's bounty of fixes affects Windows, Internet Explorer, Silverlight, Microsoft Office, Developer Tools, Forefront and SQL Server.

The update also resolves two security advisories about vulnerabilities in Microsoft Server Message Block version 2 (SMBv2) and the File Transfer Protocol (FTP) Service in Microsoft Internet Information Services (IIS).

Eight of the 13 bulletins are rated "critical." Six of those get a one on Microsoft's Exploitability Index, which is why the company advises patching them immediately.

Ben Greenbaum, senior research manager, Symantec Security Response, points to MS09-054 and MS09-062 as particularly serious.

"The primary danger the GDI+ graphics library and Internet Explorer vulnerabilities pose is that these vulnerable components are present on the majority of Windows machines," he said in an e-mailed statement. "Many of the issues addressed today are fairly trivial to exploit. For example, via a drive-by-download style attack. In that case, all a computer user would have to do to become infected by an attack using one of these vulnerabilities is unsuspectingly visit a compromised Web site."

Of the five bulletins that affect Windows 7, two -- MS09-054 and MS09-061 -- are designated "critical."

Sheldon Malm, senior director of security strategy at Rapid7, said in an e-mail that MS09-056, a flaw in the Windows CryptoAPI that could allow spoofing, is the most interesting vulnerability because of its connection to trusted Security services, even if it's not among those that need to be immediately addressed.

The flaw was used earlier this month to create a certificate, which was distributed to a security mailing list, that could have allowed a Web site to impersonate PayPal's Web site.

Qualys CTO Wolfgang Kandek said in an e-mail, "The vulnerability is rated only as 'important' because it does not allow the attacker to take over the machine, but it can be used to steal the user's credentials to any Web site."


InformationWeek has published an in-depth report on smartphone security. Download the report here (registration required).

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2011-1793
Published: 2014-12-25
rendering/svg/RenderSVGResourceFilter.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted SVG document that leads to a "stale pointer."

CVE-2011-1794
Published: 2014-12-25
Integer overflow in the FilterEffect::copyImageBytes function in platform/graphics/filters/FilterEffect.cpp in the SVG filter implementation in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified ...

CVE-2011-1795
Published: 2014-12-25
Integer underflow in the HTMLFormElement::removeFormElement function in html/HTMLFormElement.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted HTML document con...

CVE-2011-1796
Published: 2014-12-25
Use-after-free vulnerability in the FrameView::calculateScrollbarModesForLayout function in page/FrameView.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaS...

CVE-2011-1798
Published: 2014-12-25
rendering/svg/RenderSVGText.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 does not properly perform a cast of an unspecified variable during an attempt to handle a block child, which allows remote attackers to cause a denial of service (application crash) or possibly have unknown othe...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.