Microsoft Releases Mammoth Security Patch

The company's 13 security bulletins set a record and bring Windows 7 its first official fixes.

Thomas Claburn, Editor at Large, Enterprise Mobility

October 13, 2009

2 Min Read
Dark Reading logo in a gray background | Dark Reading

Microsoft on Tuesday issued 13 security bulletins covering 34 vulnerabilities as part of its regularly scheduled monthly patch cycle.

Acknowledging that this represents the most security bulletins the company has ever released, Microsoft senior security program manager Jerry Bryant played down the size issue by noting that the company has released between 10 and 12 bulletins before so "this is business as usual."

In June, the company set a record of 31 for the number of vulnerabilities fixed, not to be confused with the number of bulletins released, which was 10 that month.

This month's bounty of fixes affects Windows, Internet Explorer, Silverlight, Microsoft Office, Developer Tools, Forefront and SQL Server.

The update also resolves two security advisories about vulnerabilities in Microsoft Server Message Block version 2 (SMBv2) and the File Transfer Protocol (FTP) Service in Microsoft Internet Information Services (IIS).

Eight of the 13 bulletins are rated "critical." Six of those get a one on Microsoft's Exploitability Index, which is why the company advises patching them immediately.

Ben Greenbaum, senior research manager, Symantec Security Response, points to MS09-054 and MS09-062 as particularly serious.

"The primary danger the GDI+ graphics library and Internet Explorer vulnerabilities pose is that these vulnerable components are present on the majority of Windows machines," he said in an e-mailed statement. "Many of the issues addressed today are fairly trivial to exploit. For example, via a drive-by-download style attack. In that case, all a computer user would have to do to become infected by an attack using one of these vulnerabilities is unsuspectingly visit a compromised Web site."

Of the five bulletins that affect Windows 7, two -- MS09-054 and MS09-061 -- are designated "critical."

Sheldon Malm, senior director of security strategy at Rapid7, said in an e-mail that MS09-056, a flaw in the Windows CryptoAPI that could allow spoofing, is the most interesting vulnerability because of its connection to trusted Security services, even if it's not among those that need to be immediately addressed.

The flaw was used earlier this month to create a certificate, which was distributed to a security mailing list, that could have allowed a Web site to impersonate PayPal's Web site.

Qualys CTO Wolfgang Kandek said in an e-mail, "The vulnerability is rated only as 'important' because it does not allow the attacker to take over the machine, but it can be used to steal the user's credentials to any Web site."


InformationWeek has published an in-depth report on smartphone security. Download the report here (registration required).

About the Author

Thomas Claburn

Editor at Large, Enterprise Mobility

Thomas Claburn has been writing about business and technology since 1996, for publications such as New Architect, PC Computing, InformationWeek, Salon, Wired, and Ziff Davis Smart Business. Before that, he worked in film and television, having earned a not particularly useful master's degree in film production. He wrote the original treatment for 3DO's Killing Time, a short story that appeared in On Spec, and the screenplay for an independent film called The Hanged Man, which he would later direct. He's the author of a science fiction novel, Reflecting Fires, and a sadly neglected blog, Lot 49. His iPhone game, Blocfall, is available through the iTunes App Store. His wife is a talented jazz singer; he does not sing, which is for the best.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights