Newsletters
The Enterprise Security Supersite NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
This ad will display for the next 20 seconds. Click for more information, or
Home Network Security Viruses & Malware Cybercrime Security Solutions More Topics...
UCS Invicta: Integrated Flash
Deploy flash memory technology to
deliver peak workload performance.

Find out more>>
Network Security
Gartner's #1 for endpoint backup
Average Rating:
Rate this article:  
Analysts: Patch Microsoft IE Drive-By Vulnerability First

Analysts: Patch Microsoft IE Drive-By Vulnerability First
By Jennifer LeClaire

Share
Share on Facebook Share on Twitter Share on Linkedin Share on Google Plus

Despite the release of Windows 8 in late October, security researcher Andrew Storms noted that three of Tuesday's bulletins already affect it. Much of the core operating system is reused from version to version, even in new releases, and all software has bugs, he explained. Six security fixes total were issued as part of Microsoft's monthly Patch Tuesday.
 



Microsoft on Tuesday released six bulletins as part of its monthly patch process. The patches fix flaws in Windows, Office and .NET Framework.

Microsoft recommends IT admins apply all of the security updates as soon as possible. Redmond prioritized MS12-071, which addresses vulnerabilities in Internet Explorer, and MS12-075, which fixes issues in Windows Kernal-Mode Driver.

"We are committed to improving the security of all our products," said Dave Forstrom, director of Trustworthy Computing at Microsoft. "When security updates are released, customers who have Automatic Updates enabled will be protected automatically and do not need to take an action."

First Things First

We turned to Andrew Storms, director of security operations at nCircle, to get his take on November's Patch Tuesday. He agreed that the priority is the drive-by exploit affecting Internet Explorer 9.

"It's fairly obvious that Microsoft patched this bug in IE10 before its release. Otherwise, we would have a bulletin affecting both IE9 and IE10," Storms told us.

The second bug on his list is MS12-075. One of the bugs in this bulletin affects TrueType fonts and creates a theoretical exploit vector with third-party browsers. Storms recommended patching this one immediately after the IE9 bug.

"The .NET bug that looked problematic in last week's advanced notification is not as serious as it could have been. The remote exploit of this bug is complex; it's going to be difficult for most attackers to use," Storms said. "This is the kind of bug that is a popular tool for pen testers with local network access to show off possible attack vectors, so you should definitely patch it sooner rather than later."

IT Lockdown

Despite the release of Windows 8 in late October, Storms noted that three of Tuesday's bulletins already affect it. Much of the core operating system is reused from version to version, even in new releases, and all software has bugs, he explained. These factors, combined with security researchers that love to find and report bugs in the latest software version, he said, are reasons for the number of bulletins for Windows 8. This should surprise no one.

"Many financial and retail organizations go into IT 'lock-down' for the last few months of the year. They don't want to introduce any changes that may impact their ability to process transactions during the holiday shopping season," Storms said. "It's likely that none of today's patches will be applied to the server infrastructure of these organizations, so Microsoft's comprehensive mitigation advice is critical. It allows these organizations to mitigate the security risk without compromising downtime."

Tyler Reguly, technical manager of security research and development at nCircle, said there's really nothing to talk about with regard to Windows 8 and Server 2012. As he sees it, if you're looking for an operating system without vulnerabilities, you might as well check the end of the rainbow for a pot of gold or try to catch a unicorn.

"Microsoft's recent actions with Flash in IE10 surprised me. I've always felt Security Advisories were the geekier communication mechanism and Security Bulletins were meant for a wider audience," Reguly said. "Yet, they've made the decision to go with Security Advisories only for Flash updates, a divergence from the approach they took when XP shipped with Flash built-in."
 

Tell Us What You Think
Comment:

Name:



UCS Invicta: Integrated Flash Why wait for the future? Unlock the potential of your applications and create new business opportunities today with UCS Invicta Series Solid State Systems. Take advantage of the power of flash technology. See how it can help accelerate IT, eliminate data center bottlenecks, and deliver the peak application performance and predictability your users demand. Click here to learn more.


 Network Security
1.   Gmail Hackable by Android Apps
2.   UPS Stores Hit by Data Breach
3.   Target Data Breach Cost: $148 Million
4.   Aruba Handles Black Hat with Aplomb
5.   Chinese Hackers Steal Patient Data


advertisement
UPS Stores Hit by Data Breach
Biz must adopt better security measures.
Average Rating:
Target Data Breach Cost: $148 Million
Better customer data protection needed.
Average Rating:
FBI Cybersquad To Add Agents
Rewarded for recent security successes.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
Researchers Find Malicious Android Apps Can Hack Gmail
A new study shows that a weakness in the Android mobile operating system can be used to steal sensitive, personal info from unwitting users. Gmail proved to be the easiest app to attack; Amazon, the hardest.
 
UPS Stores in 24 States Hit by Data Breach
Big Brown has been breached. UPS said that about 105,000 customer transactions at 51 of its UPS Store locations in 24 states could have been compromised between January and August.
 
Cost of Target Data Breach: $148 Million Plus Loss of Trust
The now infamous Target data breach is still costing the company -- and its shareholders -- plenty. In fact, the retailing giant forecast the December 2013 incident cost shareholders $148 million.
 

Enterprise Hardware Spotlight
Acer's New Desktop Box Rides the Chrome OS Wave
Filling out its Chrome OS line, Acer is following the introduction of a larger Chromebook line earlier this month with a new tiny $180 desktop Chromebox and also a smaller Chromebook.
 
Feds OK $2.3 Billion IBM-Lenovo x86 Server Deal
IBM and Lenovo are celebrating U.S. approval of their x86-based server deal, having cleared some major security hurdles. The deal makes Lenovo a major player for enterprise data centers.
 
Three New Lenovo PCs Aimed at Business Users
With businesses wanting computing solutions that do more for less money, Lenovo has unveiled three new desktop PCs that it says offer solid computing at a budget-minded price.
 

Mobile Technology Spotlight
Screen Shortage Briefly Puts Brakes on iPhone 6
RAM? Check. Antenna switch? Check. Screen? Oops. Parts suppliers for Apple have found themselves facing a shortage of screens for the new iPhone 6 as next month's release date for the new smartphone looms.
 
Bounty Offered to Coders for Oculus Rift Bugs
Coders who find bugs in software for the Oculus Rift VR immersive headset could receive a reward of at least $500 under Facebook's White Hat bounty program. Facebook acquired Oculus in March.
 
Google Glass Adds Voice Access to Phone Contacts
The latest update to Google Glass will let users access their top 20 phone contacts with voice commands alone. A user can then choose a phone call, Google hangouts, e-mail or text messaging.
 

Navigation
Enterprise Security Today
Home/Top News | Network Security | Viruses & Malware | Cybercrime | Security Solutions | Mobile Security | Disaster Recovery | Windows Security
Data Security | EST Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.