Microsoft fixes 19 bugs in big patch smorgasbord
- 12 August, 2009 05:26
- Comments
Microsoft today delivered nine security updates that patched 19 vulnerabilities in several crucial components of Windows, as well as in Media Player, Outlook Express, IIS (Internet Information Server), Office and other products.
Five of the updates were pegged as "critical," the most serious ranking in Microsoft's four-step scoring system, while four were marked "important," the next rating down.
"This is certainly a hodgepodge," said Andrew Storms, director of security operations at nCircle Network Security. "There's no real pattern this month. I'd call it a smorgasbord."
Of the nine bulletins, eight patched some part of Windows or software included with the operating system, while the ninth plugged holes in a variety of programs -- Office, Visual Studio, Internet Security and Acceleration Server (ISA Server) and others -- that stemmed from a flaw in Office Web Components (OWC), a set of ActiveX controls that let users publish Word, Excel and PowerPoint documents on the Web, then view them within Internet Explorer (IE).
Last month, Microsoft warned users of attacks exploiting the ActiveX control that displays Excel spreadsheets in IE, but the company was unable to patch it in time to meet the July update schedule. Security experts had predicted that Microsoft would fix the flaw today.
Microsoft also patched Remote Desktop Connection Client for Mac, software that lets Mac users connect to Windows-based machines, along with Remote Desktop, a service present on both client and server versions of Windows. That software is used to access applications and data on a remote system over a network.
But the big story today, said Storms, were the patches for five vulnerabilities -- two of which had been disclosed and patched previously -- that Microsoft's own software inherited from a buggy code "library," dubbed ATL for Active Template Library.
Two weeks ago, Microsoft rushed a pair of emergency updates to users that plugged multiple holes in IE and Visual Studio. Those vulnerabilities were traced to ATL, which is used by Microsoft and an unknown number of third-party developers to create ActiveX controls and application components.
The ATL vulnerabilities were introduced when a Microsoft programmer added an extra "&" character to the widely-used library.
"We expected a slew of ATL patches," said Storms, "although we only got five. But I expect that we'll see more and more ATL bugs from Microsoft in the next couple of months."
Today's ATL patches included fixes for both the "public" version of the library -- what Microsoft shares with third-party developers -- and the "private" version it uses internally. The five-fix MS09-037 security bulletin plugs holes left by ATL in Outlook Express, a now-outdated light e-mail client once bundled with Windows; in Windows Media Player; and in two Microsoft-made ActiveX controls.
Storms also called out MS09-038, which patches two vulnerabilities in Windows' handling of the AVI media file format. "This is a classic example of a media file format bug that once you view a malicious video, you get owned," he said.
The AVI-handling flaws are ripe for worm exploitation. "All the potential is there," Storms said, but he declined to predict whether hackers would latch onto the vulnerabilities with in-the-wild exploits.
"We're going to feel the 19 [vulnerabilities] this month," Storms added. "Because of the disparate systems that need to be patched and the wide variety of software that must be tested, everyone will be feeling the pain this month."
The August updates can be downloaded and installed via the Microsoft Update and Windows Update services, as well as through Windows Server Update Services.
- Bookmark this page
- Share this article
- Got more on this story? Email Computerworld
- Follow Computerworld on twitter
- Two May Be Better Than One: Why Hard Disk Drives and Flash Belong Together
- Security Threat Report 2012
- Beyond Dropbox: Requirements for Enterprise Secure File Sharing
- Demonstrating Return on Investment with Enterprise-Class Identity and Access Management Technology
- FTP Replacement: Where MFT Makes Sense and Why You Should Care
- iPhone 5 rumour rollup for the week ending February 10
- 3D mapping revives underwater city
- Academic challenges Turnbull over NBN satellite criticism
- What are you saying: Telstra’s customer service slowly improving, SA minister urging Facebook to overturn its photo ban
- In pictures: Capgemini opens new Canberra office
-
Maingear's six-core laptop has 1.8TB of SSD storage
-
After Megaupload shuts, BTJunkie follows
-
Windows Event Viewer phishing scam remains active
-
NeuroSky MindWave: Fun with Brainwaves
-
20 popular Ubuntu Linux apps you may want to try
-
Microsoft Office
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Computers for Seniors for Dummies, 2nd Edition
-
MYOB Software for Dummies 6E Australian Edition
-
Office 2007 for Dummies
-
Windows 7 for Dummies®
-
Teach Yourself Visually Windows 7
-
Windows 7 for Seniors for Dummies®
-
Office 2007 All-In-One Desk Reference for Dummies












Comments
Post new comment