Newsletters
The Enterprise Security Supersite NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
This ad will display for the next 20 seconds. Please click for more information, or scroll down to pass the ad, or Close Ad.
Home Network Security Viruses & Malware Hackers Security Solutions More Topics...
APC Free White Paper
Optimize your network investment &
Enter to win a Samsung Galaxy Note

www.apc.com
Windows Security
Fiercely productive scanners
Average Rating:
Rate this article:  
Analysts: Patch Microsoft IE Drive-By Vulnerability First
Analysts: Patch Microsoft IE Drive-By Vulnerability First

By Jennifer LeClaire
November 14, 2012 10:00AM

Bookmark and Share
Despite the release of Windows 8 in late October, security researcher Andrew Storms noted that three of Tuesday's bulletins already affect it. Much of the core operating system is reused from version to version, even in new releases, and all software has bugs, he explained. Six security fixes total were issued as part of Microsoft's monthly Patch Tuesday.
 


Microsoft on Tuesday released six bulletins as part of its monthly patch process. The patches fix flaws in Windows, Office and .NET Framework.

Microsoft recommends IT admins apply all of the security updates as soon as possible. Redmond prioritized MS12-071, which addresses vulnerabilities in Internet Explorer, and MS12-075, which fixes issues in Windows Kernal-Mode Driver.

"We are committed to improving the security of all our products," said Dave Forstrom, director of Trustworthy Computing at Microsoft. "When security updates are released, customers who have Automatic Updates enabled will be protected automatically and do not need to take an action."

First Things First

We turned to Andrew Storms, director of security operations at nCircle, to get his take on November's Patch Tuesday. He agreed that the priority is the drive-by exploit affecting Internet Explorer 9.

"It's fairly obvious that Microsoft patched this bug in IE10 before its release. Otherwise, we would have a bulletin affecting both IE9 and IE10," Storms told us.

The second bug on his list is MS12-075. One of the bugs in this bulletin affects TrueType fonts and creates a theoretical exploit vector with third-party browsers. Storms recommended patching this one immediately after the IE9 bug.

"The .NET bug that looked problematic in last week's advanced notification is not as serious as it could have been. The remote exploit of this bug is complex; it's going to be difficult for most attackers to use," Storms said. "This is the kind of bug that is a popular tool for pen testers with local network access to show off possible attack vectors, so you should definitely patch it sooner rather than later."

IT Lockdown

Despite the release of Windows 8 in late October, Storms noted that three of Tuesday's bulletins already affect it. Much of the core operating system is reused from version to version, even in new releases, and all software has bugs, he explained. These factors, combined with security researchers that love to find and report bugs in the latest software version, he said, are reasons for the number of bulletins for Windows 8. This should surprise no one.

"Many financial and retail organizations go into IT 'lock-down' for the last few months of the year. They don't want to introduce any changes that may impact their ability to process transactions during the holiday shopping season," Storms said. "It's likely that none of today's patches will be applied to the server infrastructure of these organizations, so Microsoft's comprehensive mitigation advice is critical. It allows these organizations to mitigate the security risk without compromising downtime."

Tyler Reguly, technical manager of security research and development at nCircle, said there's really nothing to talk about with regard to Windows 8 and Server 2012. As he sees it, if you're looking for an operating system without vulnerabilities, you might as well check the end of the rainbow for a pot of gold or try to catch a unicorn.

"Microsoft's recent actions with Flash in IE10 surprised me. I've always felt Security Advisories were the geekier communication mechanism and Security Bulletins were meant for a wider audience," Reguly said. "Yet, they've made the decision to go with Security Advisories only for Flash updates, a divergence from the approach they took when XP shipped with Flash built-in."
 

Tell Us What You Think
Comment:

Name:



APC has an established a reputation for solid products that virtually pay for themselves upon installation. Who has time to spend worrying about system downtime? APC makes it easy for you to focus on business growth instead of business downtime with reliable data center systems and IT solutions. Learn more here.


 Windows Security
1.   Patch Tuesday Offers Critical Fixes
2.   Microsoft Pulls Plug on Windows XP
3.   Against a Wall, Some Buy XP Support
4.   Last Fixes Tuesday for XP, Office 2003
5.   Despite Its Age, XP Remains a Favorite


advertisement
Last Fixes Tuesday for XP, Office 2003
Microsoft closing out support for two.
Average Rating:
Windows 8 Updates Expected Soon
Using OS feedback, security concerns.
Average Rating:
Microsoft Pulls Plug on Windows XP
Third-party workarounds abound.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
Heartbleed Could Cost Millions, Could Have Been Prevented
Early estimates of Heartbleed’s cost to enterprises are running in the millions. The reason: revoking all the SSL certificates the bug exposed will come at a very hefty price. Some say it all could have been avoided.
 
Michaels Says Nearly 3M Credit, Debit Cards Breached
Arts and crafts retail giant Michaels Stores has confirmed that a data breach at its POS terminals from May 2013 to Jan. 2014 may have exposed nearly 3 million customer credit and debit cards.
 
Google's Street View Software Unravels CAPTCHAs
The latest software Google uses for its Street View cars to read street numbers in images for Google Maps works so well that it also solves CAPTCHAs, those puzzles designed to defeat bots.
 

Enterprise Hardware Spotlight
Vaio Fit 11A Battery Danger Forces Recall by Sony
Using a Sony Vaio Fit 11A laptop? It's time to send it back to Sony. In fact, Sony is encouraging people to stop using the laptop after several reports of its Panasonic battery overheating.
 
Continued Drop in Global PC Shipments Slows
Worldwide shipments of PCs fell during the first three months of the year, but the global slump in PC demand may be easing, with a considerable slowdown from last year's drops.
 
Google Glass Finds a Home in Medical Education, Practice
The innovative headpiece may find its niche in markets where hands-free access to data can be a big advantage. Glass experiments for doctors are already under way, with some promising results.
 

Mobile Technology Spotlight
Review: Siri-Like Cortana Fills Windows Phone Gap
With the new Cortana virtual assistant, Windows catches up with Apple's iOS and Google's Android in a major way, taking some of the best parts of Apple's and Google's virtual assistants, with new tools too.
 
With Galaxy S5, Samsung Proves Less Can Be More
Samsung has produced the most formidable rival yet to the iPhone 5s: the Galaxy S5. The device is the fifth edition of the company's successful line of Galaxy S smartphones, and shows less can be more.
 
Facebook Rolls Out Potentially Intrusive Location-Sharing
Looking for friends? Facebook users in the U.S. will soon be able to see which of their friends are nearby, using a smartphone's GPS. Could be a cool feature in some cases, or way too much information.
 

Navigation
Enterprise Security Today
Home/Top News | Network Security | Viruses & Malware | Hackers | Security Solutions | Mobile Security | Disaster Recovery | Windows Security
Data Security | EST Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.