Newsletters
The Enterprise Security Supersite NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
This ad will display for the next 20 seconds. Please click for more information, or scroll down to pass the ad, or Close Ad.
Home Network Security Viruses & Malware Hackers Security Solutions More Topics...
APC Free White Paper
Optimize your network investment &
Enter to win a Samsung Galaxy Note

www.apc.com
Windows Security
24/7/365 Network Uptime
Average Rating:
Rate this article:  
Sept. Patch Tuesday One To Remember, With 13 Bulletins
Sept. Patch Tuesday One To Remember, With 13 Bulletins

By Jennifer LeClaire
September 11, 2013 11:12AM

Bookmark and Share
Paul Henry, a security and forensics analyst at Lumension, said this month's Patch Tuesday, with its 13 bulletins and 47 patches, is a September to remember. By way of comparison, September 2012's release only contained two bulletins -- and both were rated as important. Internet Explorer, SharePoint and Outlook are hardest hit with security fixes this month.
 


Microsoft on Tuesday issued 13 security bulletins. Four are rated critical. The cumulative 47 patches address vulnerabilities in Microsoft Windows, Office, Outlook, Internet Explorer and SharePoint. Microsoft recommends focusing on MS13-067, MS13-068, and MS13-069 first.

"While the Outlook bulletin is certainly one to pay attention to, building a reliable exploit for this issue won't be easy," said Dustin Childs, group manager, Microsoft Trustworthy Computing. "Still, we've listed this update as one of our highest priorities for this month and encourage customers to deploy the bulletins to help ensure protection."

2004 Risks Real Again

Microsoft is putting top priority on MS13-067, which affects SharePoint Server. The most severe vulnerability is CVE-2013-1330, which allows remote code execution by malicious content sent to the server without user interaction, genuine real-time remote exploitation, said Ross Barrett, a senior manager of security engineering at Rapid 7.

"Of the 10 CVEs, one is public, but supposedly that is not CVE-2013-1330," he told us. "There is a workaround for CVE-2013-1330 related to enabling state inspection for message authentication code attributes."

The other two critical advisories require user interaction to trigger the vulnerabilities. However, Barrett noted that MS13-068 affecting Microsoft Outlook is particularly toxic because it can be triggered when users view malicious content in the Outlook preview pane.

"Apparently, we have gone back in time and the risks from 2004 are real again," he said. "This is pretty significant and administrators will have to move fast to patch this before exploits appear."

SharePoint Shops Beware

MS13-070 is concerning to Barrett because it only applies to XP and Server 2003, and those vulnerabilities tend to be less "contained" than more mature versions of Windows.

"If you are running an MS-heavy shop and have significantly invested in the back office technology of SharePoint and all its glorious services, then this month is going to be very busy for you," he said.

"There are lots of vulnerabilities to patch, many of which are high risk. Office vulnerabilities are typically mitigated by the fact that they require a user to interact with something malicious, either through an attachment or a link, in order to be exploited. But with the SharePoint that degree of mitigation may go away and other factors of defense-in-depth will come into play."

The Hardest Hit

We turned to Paul Henry, a security and forensics analyst at Lumension, to get his take on this month's Patch Tuesday. He told us this is definitely a September to remember. By way of comparison, September 2012's release only contained two bulletins -- and both were rated as important.

"We're seeing big numbers this month but there is perhaps some good news: only four patches are considered critical, two were publicly known yet Microsoft has not seen active attacks on any of the September CVEs to-date and none of them impact the current code base," Henry said.

IE, SharePoint and Outlook are hardest hit this month, Henry said, and vulnerabilities in XP and Windows 2003 were also patched -- a practice he hopes to see more of as the XP end-of-life date of April 8, 2014, nears. Windows 2003 has an end-of-life date of July 14, 2015. For anyone using XP, he said, a migration plan should be put in place if you do not already have one.
 

Tell Us What You Think
Comment:

Name:



APC has an established a reputation for solid products that virtually pay for themselves upon installation. Who has time to spend worrying about system downtime? APC makes it easy for you to focus on business growth instead of business downtime with reliable data center systems and IT solutions. Learn more here.


 Windows Security
1.   Patch Tuesday Offers Critical Fixes
2.   Microsoft Pulls Plug on Windows XP
3.   Against a Wall, Some Buy XP Support
4.   Last Fixes Tuesday for XP, Office 2003
5.   Despite Its Age, XP Remains a Favorite


advertisement
Last Fixes Tuesday for XP, Office 2003
Microsoft closing out support for two.
Average Rating:
Windows 8 Updates Expected Soon
Using OS feedback, security concerns.
Average Rating:
Microsoft Pulls Plug on Windows XP
Third-party workarounds abound.
Average Rating:


advertisement
Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
IBM Offers Security, Disaster Recovery as SoftLayer Service
New disaster recovery and security services for SoftLayer clients are being added by IBM. Big Blue said the new capabilities will speed cloud adoption by alleviating concern over business continuity.
 
How To Beat the Heartbleed Bug
Heartbleed headlines continue as IT admins scramble for answers no one has. Early reports of stolen personal data, including 900 social insurance numbers in Canada, are starting to trickle in.
 
After Heartbleed, OpenSSL Calls for More Support
The president of the OpenSSL Foundation says more support is needed from companies and governments that use its software so that it can better spot and fix flawed pieces of code such as Heartbleed.
 

Enterprise Hardware Spotlight
Vaio Fit 11A Battery Danger Forces Recall by Sony
Using a Sony Vaio Fit 11A laptop? It's time to send it back to Sony. In fact, Sony is encouraging people to stop using the laptop after several reports of its Panasonic battery overheating.
 
Continued Drop in Global PC Shipments Slows
Worldwide shipments of PCs fell during the first three months of the year, but the global slump in PC demand may be easing, with a considerable slowdown from last year's drops.
 
Google Glass Finds a Home in Medical Education, Practice
Google Glass may find its first markets in verticals in which hands-free access to data is a boon. Medicine is among the most prominent of those, as seen in a number of Glass experiments under way.
 

Mobile Technology Spotlight
Amazon 3D Smartphone Pics Leaked
E-commerce giant Amazon is reportedly set to launch a smartphone after years of development. Photos of the phone, which may feature a unique 3D interface, were leaked by tech pub BGR.
 
Zebra Tech Buys Motorola Enterprise for $3.45B
Weeks after Lenovo bought Motorola Mobility’s assets from Google for $2.91 billion, Zebra Technologies is throwing down $3.45 billion for Motorola’s Enterprise business in an all-cash deal.
 
CTIA Caves, Volunteers Kill Switch Plan
After bucking against the concept of a smartphone kill switch, the CTIA just announced the “Smartphone Anti-Theft Voluntary Commitment” to thwart smartphone thefts in the U.S.
 

Navigation
Enterprise Security Today
Home/Top News | Network Security | Viruses & Malware | Hackers | Security Solutions | Mobile Security | Disaster Recovery | Windows Security
Data Security | EST Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.