The Enterprise Security Supersite
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home Network Security Viruses & Malware Spam & Hackers Security Products More Topics...
Computing
Average Rating:
Rate this article:  
IE Vulnerability Heads Microsoft IE Vulnerability Heads Microsoft's Patch Tuesday List
By Jennifer LeClaire
December 4, 2009 8:08AM

Bookmark and Share
Patch Tuesday will address a vulnerability in Internet Explorer severe enough that Microsoft considered an out-of-band patch. Microsoft's Patch Tuesday also addresses a Windows Server 2008 flaw that could be disruptive and a Project 2000 problem. A recently announced TLS flaw in browsers and servers is apparently not patched.
 


The coming week will be a busy one for IT Relevant Products/Services administrators. Microsoft plans to release six patches for December's Patch Tuesday -- three rated critical and three important. The patches will address 12 vulnerabilities in Windows Relevant Products/Services, Internet Explorer, and Microsoft Office.

"To help customers plan for their deployment of these updates, I want to specifically call out that they touch all supported versions of Windows and IE," said Jerry Bryant of the Microsoft Security Response Center. "On the Office side, the bulletins impact Project, Word and Works 8.5. All of the updates for Windows will require a restart, so please plan accordingly."

Patching the IE Flaw

At the top of the list for IT administrators -- and at the top of Microsoft's deployment list -- is a vulnerability in IE 6 and 7 that could lead to remote code execution. Although Microsoft is not aware of any active attacks that seek to exploit this vulnerability, it is severe enough that the company considered releasing an out-of-band patch on Nov. 23.

The IE fix is part of Bulletin 4, which will have the broadest impact because it will affect all user machines across an entire organization, according to Don Leatham, Lumension senior director of solutions and strategy.

"It is critical across Windows 7, Vista and XP; requires a restart; and impacts all versions of Internet Explorer 6, 7 and 8," Leatham said. "We suggest that IT departments be prepared to quickly assess and patch all end-user machines throughout their organization."

Disrupting Windows Server

Bryant said the other critical update affecting Windows is in Bulletin 1. Although this bulletin has a critical severity rating, he said, the lower risk will drop the deployment priority down a little. But security Relevant Products/Services researchers said the importance shouldn't be underestimated for Windows Server 2008 users.

"If IT teams have Windows Server 2008 deployed in support of mission-critical applications, this update could be disruptive," Leatham said. "If the associated vulnerabilities are rated high on Microsoft's exploitability scale, organizations may be forced to pull production servers out of service for patching."

Bulletin 3 is critical for Project 2000. Since the majority of people use later versions of Microsoft Project, Leatham said, any attack associated with this update should be fairly narrow. Nonetheless, he added, IT teams should ensure that they have identified all instances of Project 2000 that may still exist in their organization.

What about the TLS Flaw?

Leatham said it appears that Microsoft isn't issuing a patch for the recently announced TLS flaw that will most likely force updates to all brands of browsers and all Internet servers using SSL/TLS. The flaw allows attackers to inject text into encrypted traffic.

"Although we'll have to wait until Patch Tuesday for confirmation, we are led to believe that Microsoft has chosen not to address this vulnerability in this round of patches," Leatham said. "There is controversy in the security community as to the true importance of speeding a fix to market for this flaw, and no widespread exploits have been reported."
 

Tell Us What You Think
Comment:

Name:



Advertisement


 Computing
1.   BlackPad Tablet Expected from RIM
2.   Windows 7 Being Retooled for Tablets
3.   HP Plans Windows, webOS Tablets
4.   U.S. Orders for Dell Streak Overflow
5.   Safari 5.0.1 Offers Extensions Gallery


advertisement
Bing, Yahoo Search Gains QuestionedBing, Yahoo Search Gains Questioned
Contextual approach inflates audience.
Average Rating:
Suit Says eBay Stole PayPal IdeaSuit Says eBay Stole PayPal Idea
XPRT claims patent before eBay.
Average Rating:
Mozilla Releases First Firefox 4 BetaMozilla Releases First Firefox 4 Beta
Browser supports Google's WebM.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Navigation
Enterprise Security Today
Home/Top News | Network Security | Viruses & Malware | Spam & Hackers | Security Products | Mobile Security | Disaster Recovery | Windows Security
Data Security | EST Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.