The Enterprise Security Supersite
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home Network Security Viruses & Malware Spam & Hackers Security Products More Topics...
Windows Security
Average Rating:
Rate this article:  
Five Critical Patches Issued for Internet Explorer Five Critical Patches Issued for Internet Explorer
By Jennifer LeClaire
December 9, 2009 8:06AM

Bookmark and Share
Microsoft's Patch Tuesday focuses on critical vulnerabilities in Internet Explorer, and previously undisclosed IE8 problems call Microsoft's quality assurance into question. Other patches fix random things and should be tested before deployment, nCircle's Tyler Reguly advises. A critical patch for Windows Server 2008 will require a restart.
 


Another Patch Tuesday, another batch of fixes for critical issues. In December's cycle, Microsoft issued six security bulletins that address 12 vulnerabilities, seven rated as critical. Five of those critical updates fix issues in Internet Explorer that could be used in drive-by attacks.

"Proof-of-concept exploit code was released for the object memory corruption vulnerability late last month, but it wasn't reliable," said Ben Greenbaum, senior research manager for Symantec Security Response. "It's been a race since between Microsoft and attackers to either get a patch out or improve the exploit's reliability. As it turns out, Symantec has yet to see either the exploit's consistency increased significantly nor any successful attacks using it in the wild."

Microsoft Under Scrutiny

Any improvement in browsing security is a nice holiday gift to consumers surfing through their inboxes every morning for the best holiday shopping deals, said Andrew Storms, director of security operations for nCircle. However, he added, Microsoft's secure-code development practices are going to come under scrutiny again because the IE update includes fixes for two previously nonpublic exploits that only affect IE8, the newest browser from Microsoft.

"There's no way for Microsoft to avoid the speculation that these bugs should have been found during the software development and quality assurance cycle, but the reality is that this was bound to happen," Storms said. "Every product has bugs, and more features means greater attack surfaces. It is depressing for both Microsoft and its customers, though, that it happened so quickly."

Beyond the IE Flaws

Beyond IE, December's Patch Tuesday list is really a mashup of random fixes, said Tyler Reguly, senior security engineer at nCircle. There's a lot of letters with LSASS, ADFS and IAS and a smattering of client-side vulnerabilities, but in the grand scheme of things, he said, there's nothing extremely dangerous once you get past IE.

"Given some of the configurations that are affected, it's definitely worth taking the time to test these patches in your lab before deploying them. IE is, of course, the exception to that recommendation," Reguly said.

"The non-security update for Integrated Windows Authentication on IIS and other web-based systems is rather interesting. This was not fixed via a security bulletin, but it's great to see it shipping nonetheless," he added. "Essentially, this fix provides a method to protect web clients from credential-forwarding attacks, which will only help to improve intranet security."

Shoring Up Against Malware Threats

Although there are several critical patches that need to be addressed this month, the big so-what for Microsoft patches centers around the ubiquitous MS09-072 affecting all versions of Internet Explorer and carrying Microsoft's highest exploitability rating, said Paul Zimski, vice president of market strategy for Lumension.

"This, combined with subsequent updates issued in Apple's Java for OS X, Adobe's Flash Player, and AIR, make this month particularly important to shore up patches and protect against web-borne malware threats," Zimski said.

"Bulletin MS09-071 is also rated critical for Windows Server 2008 and requires a restart. Since Windows Server 2008 is most likely deployed in support of mission-critical applications, this update could be disruptive to business operations. Microsoft's exploitability scale for this bulletin is less severe, but organizations should address this expeditiously."
 

Tell Us What You Think
Comment:

Name:



Advertisement


 Windows Security
1.   Fix Your Internet Explorer Annoyances
2.   Patch Fixes SMB Danger from Within
3.   August Patch Flood Will Keep IT Busy
4.   Emergency MS Patch Fixes Shortcuts
5.   Windows 7: Secrets of the Start Menu


advertisement
Fix Your Internet Explorer AnnoyancesFix Your Internet Explorer Annoyances
Love it or hate it, you probably use it.
Average Rating:
Patch Fixes SMB Danger from WithinPatch Fixes SMB Danger from Within
Outside worker could bring in attack.
Average Rating:
August Patch Flood Will Keep IT BusyAugust Patch Flood Will Keep IT Busy
Traditional defenses may be obsolete.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Navigation
Enterprise Security Today
Home/Top News | Network Security | Viruses & Malware | Spam & Hackers | Security Products | Mobile Security | Disaster Recovery | Windows Security
Data Security | EST Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.