The Enterprise Security Supersite NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
Home Network Security Viruses & Malware Cybercrime Security Solutions More Topics...
GET RECOGNIZED
Let an ISACA® certification elevate your career.
Register today and save
You are here: Home / Windows Security / Patch Tuesday Focus Partly on Office
DDoS Protection Powered By Verisign
Microsoft Patch Tuesday To Bring Heavy Office Emphasis
Microsoft Patch Tuesday To Bring Heavy Office Emphasis
By Jennifer LeClaire / Enterprise Security Today Like this on Facebook Tweet this Link thison Linkedin Link this on Google Plus
PUBLISHED:
MARCH
08
2013


Call it March Madness. Microsoft on Tuesday will roll out seven security bulletins. Four of the bulletins are rated critical and three are rated important -- and some require restarts.

The critical bulletins affect Microsoft Windows, Silverlight for Office, and Microsoft Server software. The other bulletins aim to fix vulnerabilities in Office and Windows.

"IT admins can't seem to catch a break this year. First, the never-ending stream of Java issues that has kept folks on their toes since January," said Paul Henry, a security and forensic analyst at Lumension. "Now they've got another busy month of patches ahead of them, with seven total patches from Microsoft, four of which are critical. However, once again the issues outside of Microsoft will likely eclipse the Patch Tuesday issues this month."

A Heavy Office Focus

Ross Barrett, senior manager of security engineering at Rapid 7, told us it was interesting that Bulletin 1 does not list Internet Explorer 10 on Windows 7 as vulnerable. It may be an omission, he said, or it may be that the fix was included when IE 10 was released for Windows 7 systems last week. Regardless, he said, this is where he would prioritize his patching efforts.

"From this vantage, my gut feel is that Bulletin 3 is the second most important to patch, followed by either of the two other critical issues," Barrett said. "The information disclosure issues in Office I would patch when it isn't going to impact your users in any way. One of them, at least, will not require a restart."

Barrett also pointed to Bulletin 4, which is only an "elevation of privilege" vulnerability. Still, he said, it's listed as critical. That may mean that it is remotely exploitable with a known user name, or that it is already being exploited in the wild.

Meanwhile, Bulletin 2 is listed as critical in Silverlight, which is interesting to Barrett since Silverlight is not among Microsoft's most popular apps. He suggested users who have installed Silverlight should deploy this patch quickly since the risk would be on par with a Flash vulnerability.

"The focus has changed direction from last month, where Office wasn't addressed, to four of seven advisories this month relating to Office," Barrett said. "It seems likely that the seventh bulletin is another Windows kernel or kernel driver issue, since it is a core operating system vulnerability, requires a restart, and the risk is elevation of privilege."

PWN2OWN Results

In other security news, the ZDI's PWN2OWN competition is going on at the CanSecWest security conference in Vancouver. PWN2OWN awards prizes ranging from $20,000 to $100,000 to security researchers that demonstrate vulnerabilities in Adobe Flash, Adobe Reader, Google Chrome, Internet Explorer, Firefox and Java.

"In Wednesday's run, prizes have been claimed for Oracle Java by James Forshaw, Oracle Java again by Joshua Drake, IE10 on Windows 8 by VUPEN, Google Chrome on Windows 7 by a team from MWR Labs, John and Nils, and finally Mozilla Firefox and Oracle Java, both by the team at VUPEN," said Wolfgang Kandek, CTO at Qualys. "You can expect patches for these vulnerabilities to be released over the coming weeks."

Tell Us What You Think
Comment:

Name:

Like Us on FacebookFollow Us on Twitter
TOP STORIES NOW
MAY BE OF INTEREST
Salesforce.com is the market and technology leader in Software-as-a-Service. Its award-winning CRM solution helps 82,400 customers worldwide manage and share business information over the Internet. Experience CRM success. Click here for a FREE 30-day trial.
MORE IN WINDOWS SECURITY
Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
Russian Gang with Stolen IDs Hacks Hosting Company
In August, a Russian cyber gang obtained what researchers called “the largest cache of stolen data." Now, those hackers may be putting their ill-gotten gains to criminal use.
 
Dairy Queen Latest Retailer To Report Hack
Known for its hot fries and soft-serve ice cream, Dairy Queen just made cyber history as the latest victim of a hack attack. The fast food chain said that customer data at some stores may be at risk.
 
Lessons from the JPMorgan Chase Cyberattack
JPMorgan Chase is investigating a likely cyberattack. The banking giant is cooperating with law enforcement, including the FBI, to understand what data hackers may have obtained.
 

Enterprise Hardware Spotlight
AMD's New FX Series CPU Breaks Processing Speed Record
The new FX-8370 processor from Advanced Micro Devices has set a record for silicon processor speed, the company announced. Overclocked, the eight-core chip was measured at 8722.78 MHz.
 
Intel Intros Lightning-Fast PC Processors
Call it extreme. Intel just took the covers off its first-ever eight-core desktop processor, which is aimed at hardcore power users who expect more than the status quo from their computers.
 
HP Previews ProLiant Gen9 Data Center Servers
Because traditional data center and server architectures are “constraints” on businesses, HP is releasing new servers aimed at faster, simpler and more cost-effective delivery of computing services.
 

Mobile Technology Spotlight
Rumor Mill Puts Mobile Wallet in iPhone 6
Apple is moving toward the mobile wallet world with its next iPhone. The tech giant has partnered with retailers, banks and major payment networks to make it happen, according to Bloomberg.
 
Will iPhone Finally Catch Up with NFC Mobile Payment Ability?
Apple's latest version of the iPhone may have a mobile wallet to pay for purchases with a tap of the phone. The iPhone 6 reportedly is equipped with near-field communication (NFC) technology.
 
Visual Search To Shop: Gimmick or Game Changing?
Imagine using your phone to snap a photo of the cool pair of sunglasses your friend is wearing and instantly receiving a slew of information about the shades along with a link to order them.
 

Navigation
Enterprise Security Today
Home/Top News | Network Security | Viruses & Malware | Cybercrime | Security Solutions | Mobile Security | Disaster Recovery | Windows Security
Data Security | EST Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.