Vulnerabilities / Threats

3/9/2010
03:28 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Microsoft Fixes Eight Bugs, Warns Of IE Zero-Day

A light Patch Tuesday brings word of a new zero-day vulnerability in Internet Explorer 6 and 7.

Microsoft's March patch day arrives as a mixed blessing for IT administrators. On the one hand, Microsoft is releasing only two security bulletins to address eight vulnerabilities in Windows and Microsoft Office.

In terms of severity, both bulletins are merely "important." They affect Windows Movie Maker and Microsoft Office Excel. All versions of Office are affected, including Mac Office 2004 and 2008.

That's a welcome relief after last month's set of 13 bulletins addressing 26 vulnerabilities.

On the other hand, Microsoft is also warning about a new zero-day vulnerability affecting Internet Explorer 6 and 7, but not Internet Explorer 8.

Microsoft attributes the problem to an an invalid pointer reference within Internet Explorer that can, under certain conditions, be accessed after an object is deleted. An attacker can potentially exploit this vulnerability for remote code execution.

"At this time, we are aware of targeted attacks attempting to use this vulnerability," Microsoft states in its advisory. "We will continue to monitor the threat environment and update this advisory if this situation changes."

The last zero-day vulnerability in Internet Explorer was identified in January following Google's disclosure of the "Operation Aurora" cyber attack from China.

"It's a vote of confidence for IE 8 and a reminder that IE 6 is at the end of its life and should be," said Andrew Storms, director of security operations at nCircle Network Security, in phone interview.

With regard to the advisories, Storms says that the "important" severity rating reflects the need for user interaction to exploit these vulnerabilities.

Wolfgang Kandek, CTO of Qualys explains in a blog post that an attacker needs to trick the target into opening a malicious Excel document to execute the attack. "Exploitability is high for the majority of vulnerabilities listed, so we suggest to put this patch on a fast installation schedule," he says.

The situation is similar with Windows Movie Maker, according to Kandek: The user has to open a malicious file to launch an attack. He notes that Windows XP and Vista ship with vulnerable versions of the movie making software, and that while Windows 7 does not, a user could download and install version 2.6, which is affected. "The bulletin does not provide a patch for the also affected Windows Producer, a little used multimedia add-on to PowerPoint," he says.

Storms says that the Excel bulletin is interesting because it's the first bug addressed in Microsoft's recent Excel 2007 file format. Older Microsoft Office file formats, he says, are easier to attack.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
New Mexico Man Sentenced on DDoS, Gun Charges
Dark Reading Staff 5/18/2018
Cracking 2FA: How It's Done and How to Stay Safe
Kelly Sheridan, Staff Editor, Dark Reading,  5/17/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Flash Poll
[Strategic Security Report] Navigating the Threat Intelligence Maze
[Strategic Security Report] Navigating the Threat Intelligence Maze
Most enterprises are using threat intel services, but many are still figuring out how to use the data they're collecting. In this Dark Reading survey we give you a look at what they're doing today - and where they hope to go.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-10428
PUBLISHED: 2018-05-23
ILIAS before 5.1.26, 5.2.x before 5.2.15, and 5.3.x before 5.3.4, due to inconsistencies in parameter handling, is vulnerable to various instances of reflected cross-site-scripting.
CVE-2018-6495
PUBLISHED: 2018-05-23
Cross-Site Scripting (XSS) in Micro Focus Universal CMDB, version 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.0, CMS, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1 and Micro Focus UCMDB Browser, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1. This vulnerability could be remotely exploited to al...
CVE-2018-10653
PUBLISHED: 2018-05-23
There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
CVE-2018-10654
PUBLISHED: 2018-05-23
There is a Hazelcast Library Java Deserialization Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
CVE-2018-10648
PUBLISHED: 2018-05-23
There are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.