Newsletters
The Enterprise Security Supersite NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
Home Network Security Viruses & Malware Cybercrime Security Solutions More Topics...
Windows Security
Next Generation Data Center Is Here!
Average Rating:
Rate this article:  
Microsoft Security Patches Rolling Hard and Fast in 2013
Microsoft Security Patches Rolling Hard and Fast in 2013

By Jennifer LeClaire
March 13, 2013 12:32PM

Bookmark and Share
"We can only hope that this increase is due to a combination of new platforms and better discovery of vulnerabilities, rather than actual ongoing security problems at Microsoft," said security analyst Paul Henry. In 2013, Microsoft is averaging close to nine security patches monthly, including four critical fixes.
 


Just three months into 2013, and a disturbing trend is manifesting at Microsoft: There are a higher number of patches -- and, particularly, critical patches.

In 2012 Microsoft was averaging seven patches, only two of which were critical, each Patch Tuesday. In 2013, Microsoft is averaging close to nine patches monthly, including four critical fixes.

"To really put things in perspective, by March of 2011, Microsoft was averaging close to six patches, with around one critical patch," said Paul Henry, a security and forensic analyst at Lumension. "We can only hope that this increase is due to a combination of new platforms and better discovery of vulnerabilities, rather than actual ongoing security problems at Microsoft."

Top Three Priorities

Microsoft on Tuesday issued seven patches, four rated critical. As Henry sees it, the priority is MS13-021, which is a critical patch for Internet Explorer, addressing nine vulnerabilities. Fortunately, he said, none of these "use after free" issues are being publicly exploited.

"Use after free" is receiving more attention recently. However, he emphasized that it's not the delivery mechanism that's a problem. The problem is not taking care of the end game: preventing unauthorized binary from running on your machine in the first place.

"MS13-022 is your second priority. It's a critical update for a remote code execution issue in Silverlight 5. This browse-and-own attack is a pretty standard one, where users might browse to a Web site that has malicious content," Henry said.

"MS13-027 should be your third priority for patching this month, even though it's ranked important by Microsoft because it requires physical access to pull off. Regardless, it's a pretty scary vulnerability. This is an elevation of privilege in kernel mode drivers. Normally, with this sort of vulnerability, a low-level authorized user might be elevated to the system level. However, this one is a little different."

Just Like in the Movies

Andrew Storms, director of security operations at nCircle, agrees that MS13-027 is a serious vulnerability. It allows anyone with a USB stick loaded with attack code and physical access to a computer to subvert security controls. If these conditions are met, he explained, the attack would be successful even if auto-run was disabled and the screen was locked.

"You've seen this attack method in movies for years, and it's now showing in enterprises all over the world," Storms said. "Just imagine what a properly motivated janitorial staff could do with this vulnerability in just one evening. This vulnerability also seriously impacts security on all those public kiosks and co-location centers that don't have locked cabinets. The potential for harm with this vulnerability can't be overstated."

The good news is you don't need to put glue in your USB ports to protect yourself, he said. Either install the patch ASAP, or deploy a Group Policy Object setting to temporarily disable USB ports until the patch is completely deployed.

An Office-Heavy Month

Tyler Reguly, technical manager of security research and development at nCircle, calls March an "Office-heavy" month. The release includes patches for OneNote, Visio and Office for Mac.

"It's interesting that none of the core Office products are patched -- I suspect we'll see them next month," he said. "Today's top priority is the usual suspect, Internet Explorer. This has started to become routine and I'll be more surprised when we have a month where it's not at the top of the list."
 

Tell Us What You Think
Comment:

Name:



APC has an established a reputation for solid products that virtually pay for themselves upon installation. Who has time to spend worrying about system downtime? APC makes it easy for you to focus on business growth instead of business downtime with reliable data center systems and IT solutions. Learn more here.


 Windows Security
1.   Barracuda Secures Microsoft Azure
2.   Windows 7 Ends Mainstream Support
3.   Cybercrime Ring Uncovered in Brazil
4.   Fix on Way for Win 8.1 Upgrade Woes
5.   Android, Win Phone To Get Kill Switch


advertisement
Windows 7 Ends Mainstream Support
But extended support still available.
Average Rating:
Barracuda Secures Microsoft Azure
With updated Web Application Firewall.
Average Rating:
Cybercrime Ring Uncovered in Brazil
Malware hit the boleto payment system.
Average Rating:


advertisement
Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
New 'Backoff' Malware Slips Undetected into Retail Systems
'Malicious actors' are using a new variety of malware to access consumer payment data remotely through point-of-sale systems, according to a report from the Department of Homeland Security.
 
IBM Beefs Up Identity Intelligence Security Solutions
Big Blue is betting big on identity intelligence. IBM just acquired a private firm with security software to govern user access to apps and data across cloud and on-premise environments.
 
USB Security Flaw Lets Hackers Hijack PCs
Hackers can use the firmware that controls USB functions to take control of computers, say security experts. That means there may be a new class of attack for which there are no defenses.
 

Enterprise Hardware Spotlight
AMD's ARM-Based Opteron Out in $3K Dev Kit
It's dubbed "Seattle" and it's AMD's first 64-bit ARM-based Opteron processor. The low-power chip is being released as part of AMD’s Opteron A1100-series developer kit, and aimed at high-end data center needs.
 
Apple Updates MacBook Pros, Cuts Prices Up to $100
The popular MacBook Pro laptop line just got an update and a price cut of as much as $100. The MacBook Pro with Retina display now includes faster processors and double the memory.
 
Dell, BlackBerry Not Sweating Apple-IBM Alliance
IBM's recent move to partner with Apple to sell iPhones and iPads loaded with corporate applications has excited investors in both companies, but two rivals say they are unperturbed for now.
 

Mobile Technology Spotlight
BlackBerry Messenger Now Available on Windows Phone
BlackBerry's free Messenger chatting and voice app is out of beta and widely available for Windows Phone users, the company said. BBM offers secure messaging, Groups, Voice, Channels and more.
 
Virgin Mobile Offers Custom Smartphone Plans
As the wireless carrier wars continue heating up, Virgin Mobile just threw the customization coal onto the fire. The firm has debuted a no-annual-contract plan with rates based on individual use.
 
Collaboration Provider Asana Revamps Mobile App
Asana, a collaboration software provider started by a Facebook founder, is now out with a rebuilt native iOS mobile app. It replaces one that even the company admits was not up to par.
 

Navigation
Enterprise Security Today
Home/Top News | Network Security | Viruses & Malware | Cybercrime | Security Solutions | Mobile Security | Disaster Recovery | Windows Security
Data Security | EST Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.