HOME     MENU     SEARCH     NEWSLETTER    
THE ENTERPRISE SECURITY SUPERSITE. UPDATED 11 MINUTES AGO.
You are here: Home / Data Security / 11 Fixes, 7 Critical for Patch Tuesday
Build Apps 5x Faster
For Half the Cost Enterprise Cloud Computing
On Force.com
Microsoft's Patch Tuesday Brings Seven Critical Fixes
Microsoft's Patch Tuesday Brings Seven Critical Fixes
By Jennifer LeClaire / Enterprise Security Today Like this on Facebook Tweet this Link thison Linkedin Link this on Google Plus
PUBLISHED:
APRIL
10
2012


Microsoft on Tuesday issued six security bulletins to patch 11 vulnerabilities. Seven of the patches are rated critical.

"The most prominent vulnerabilities are in Internet Explorer, with 4 of the 5 patches marked as critical," John Harrison, group product manager for Symantec Security Response told us after the announcement. "Because the vulnerabilities could allow remote code execution, we recommend users patch as soon as possible."

Indeed, MS12-023 affects all versions of IE. Attacks can exploit the vulnerabilities by setting up a malicious Web page, according to Wolfgang Kandek, CTO of Qualys. We asked him to expound on the patch and how critical it really is.

"MS12-023 has an Exploitability Index of 1, meaning that Microsoft believes that an attack can be crafted within the next 30 days," Kandek said. "By the way, this update does not include the fix for the vulnerability found during last month's PWN2OWN contest at CanSecWest 2012, which will probably be fixed by another IE update next month."

Deploy Now!

Not all security researchers agree on which patches to deploy first. Andrew Storms, director of security operations at nCircle, said it must be a blue moon month because Microsoft is shipping an IE security bulletin but, for the first time in a long time, it won't be on the top of the deployment priority list. He sees another, more critical, issue.

"The 'deploy now' bulletin this month is MS12-027, a bulletin affecting the Windows Common Controls. This component is included in so many Microsoft programs it affects almost every Microsoft user on the planet," Storms said. "It gets worse: Microsoft has already seen exploits for this vulnerability in the wild in limited attacks."

Tyler Reguly, technical manager of security research and development at nCircle, said the work involved in patching every platform affected by MS12-027 may overwhelm smaller shops.

"This bulletin is a great example of why developers should use shared libraries wherever possible," Reguly said. "This should be a simple Windows patch but instead we're seeing every affected application patch the problem independently."

Other Vulnerability News

We also caught up with Paul Henry, a security and forensic analyst at Lumension, to get the broader view of patching during the week. Beyond Apple's Java nightmare last week, he pointed to issues with Adobe, Google and Mozilla worth noting.

"Another recent patch worth mentioning this Patch Tuesday comes from Adobe that fixes two critical vulnerabilities in Flash Player across Solaris, Linux, Mac OS X and Windows platforms," Henry said.

"Google released multiple patches for Chrome this Patch Tuesday period. The latest patch on April 9th addressed 12 security issues and followed the previous patch released just eight days earlier. Mozilla added vulnerable Java Plug-ins to its black list in efforts to protect users in its latest patch."

Tell Us What You Think
Comment:

Name:

Like Us on FacebookFollow Us on Twitter
TOP STORIES NOW
MAY INTEREST YOU
ISACA® offers a global community of more than 115,000 IS/IT constituents in over 180 countries. We develop and deliver industry-leading certifications, education, research and business frameworks. We equip individuals to be leaders in the fast-changing world of information systems and IT - Learn More>
MORE IN DATA SECURITY
Product Information and Resources for Technology You Can Use To Boost Your Business

NETWORK SECURITY SPOTLIGHT
Here we go again -- or should that be “Regin”? That’s the name security firm Symantec has given to an “advanced piece of malware” used in systematic spying campaigns at least as far back as 2008.

ENTERPRISE HARDWARE SPOTLIGHT
Doctor Who had K-9, the robot dog that accompanied him on adventures through space. Now, Mountain View has K5, a 5-foot-tall, 300-pound robot security guard patrolling in the Bay Area.

© Copyright 2014 NewsFactor Network, Inc. All rights reserved. Member of Accuserve Ad Network.