The Enterprise Security Supersite NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
Home Network Security Viruses & Malware Cybercrime Security Solutions More Topics...
Gartner ranks Druva #1
in overall product rating for enterprise endpoint backup
for the second year in a row!
You are here: Home / Windows Security / Patch Tuesday Promises a Busy July
Next Generation Data Center Is Here!
Patch Tuesday Promises a Busy July for IT
Patch Tuesday Promises a Busy July for IT
By Jennifer LeClaire / Enterprise Security Today Like this on Facebook Tweet this Link thison Linkedin Link this on Google Plus
PUBLISHED:
JULY
09
2013


Microsoft on Tuesday released security bulletins to patch six critical flaws in its software. The fixes address vulnerabilities in all currently supported versions of Windows, as well as browser versions IE 6 and newer, Office, Visual Studio, Lync, the .NET framework and Silverlight.

Ross Barrett, senior manager of security engineering at Rapid 7, said July's Patch Tuesday is the "polar opposite of June's ho-hum, here-we-go-again-with-the-patches exercise." In his assessment, it's going to be a busy month for security teams.

Setting Priorities

Tyler Reguly, technical manager of security research and development at Tripwire, told us the repeated mention of a CVE-2013-3129 in three bulletins jumps out at him. He urged everyone to make sure they are fully patched against this vulnerability.

"With so many critical bulletins, it's difficult to determine a solid patch priority. Luckily, there's safety in the known, so customers should patch Internet Explorer first, a common theme for Microsoft patch drops," Reguly said.

"Microsoft is patching a public vulnerability patched in MS13-053 and anything that is already public deserves extra attention, so apply the MS13-053 patch as soon as you're finished applying MS13-055."

The New Policy

We turned to Craig Young, a Tripwire security researcher, to get his take on the releases. He told us Microsoft is taking a big step toward minimizing vulnerable applications in its various app stores.

"Under the new policy, any app in any of the four app stores will be given 180 days to resolve reported code execution bugs," Young said. "This policy applies to third-party developers as well as Microsoft's own applications and is a great addition to Microsoft's existing policy of scanning and reviewing app submissions."

Internet Explorer vulnerabilities this month made up half the CVEs addressed in the July bulletin. Young said this was particularly alarming because 16 of the 17 issues addressed were memory corruption vulnerabilities -- many of which Microsoft expected could be reliably exploited in the next 30 days. What's more, he said, this comes on the heels of a particularly large June Internet Explorer update.

"Font processing took a big hit this month. Three advisories are being released to address TTF parsing issues which could be used in drive-by-downloads or other attacks leading code execution," he said. "One such vulnerability is particularly bad as it exists within kernel-space and can allow code execution in the system context."

Add Adobe to the Mix

On top of the busy month of Microsoft patches, Adobe is releasing new versions of three products addressing security flaws: Adobe Shockwave (APSB13-18), ColdFusion (APSB13-19) and Adobe Shockwave Flash player (APSB13-17).

"Users of Internet Explorer 10 and Google Chrome already have updates integrated and do not need to worry about installing the new version themselves," said Wolfgang Kankek, CTO at Qualys. "Everybody else, including Mac OS X users, should apply this critical update as quickly as possible."

Kandek also warned to keep an important point in mind: July is not over. Oracle plans to release its quarterly update for its software -- except Java -- next on July 19.

Tell Us What You Think
Comment:

Name:

Like Us on FacebookFollow Us on Twitter
TOP STORIES NOW
MAY BE OF INTEREST
IT departments are embracing cloud backup, but there's a lot you need to know before choosing a service provider. Learn all the critical things you need to know by accessing the white paper, "5 Things You Didn't Know About Cloud Backup". Access the White Paper now.
MORE IN WINDOWS SECURITY
Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
Russian Gang with Stolen IDs Hacks Hosting Company
In August, a Russian cyber gang obtained what researchers called “the largest cache of stolen data." Now, those hackers may be putting their ill-gotten gains to criminal use.
 
Dairy Queen Latest Retailer To Report Hack
Known for its hot fries and soft-serve ice cream, Dairy Queen just made cyber history as the latest victim of a hack attack. The fast food chain said that customer data at some stores may be at risk.
 
Lessons from the JPMorgan Chase Cyberattack
JPMorgan Chase is investigating a likely cyberattack. The banking giant is cooperating with law enforcement, including the FBI, to understand what data hackers may have obtained.
 

Enterprise Hardware Spotlight
AMD's New FX Series CPU Breaks Processing Speed Record
The new FX-8370 processor from Advanced Micro Devices has set a record for silicon processor speed, the company announced. Overclocked, the eight-core chip was measured at 8722.78 MHz.
 
Intel Intros Lightning-Fast PC Processors
Call it extreme. Intel just took the covers off its first-ever eight-core desktop processor, which is aimed at hardcore power users who expect more than the status quo from their computers.
 
HP Previews ProLiant Gen9 Data Center Servers
Because traditional data center and server architectures are “constraints” on businesses, HP is releasing new servers aimed at faster, simpler and more cost-effective delivery of computing services.
 

Mobile Technology Spotlight
Rumor Mill Puts Mobile Wallet in iPhone 6
Apple is moving toward the mobile wallet world with its next iPhone. The tech giant has partnered with retailers, banks and major payment networks to make it happen, according to Bloomberg.
 
Will iPhone Finally Catch Up with NFC Mobile Payment Ability?
Apple's latest version of the iPhone may have a mobile wallet to pay for purchases with a tap of the phone. The iPhone 6 reportedly is equipped with near-field communication (NFC) technology.
 
Visual Search To Shop: Gimmick or Game Changing?
Imagine using your phone to snap a photo of the cool pair of sunglasses your friend is wearing and instantly receiving a slew of information about the shades along with a link to order them.
 

Navigation
Enterprise Security Today
Home/Top News | Network Security | Viruses & Malware | Cybercrime | Security Solutions | Mobile Security | Disaster Recovery | Windows Security
Data Security | EST Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.