Saturday | 30 August, 2008
Computerworld
Microsoft patches critical bugs in Windows graphics system
Microsoft issued a critical patch for two vulnerabilities in the core graphics subsystem of Windows as one of eight fixes released Tuesday
Computerworld Buyer's Guide - Vendors Matched to this Article
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.

Newsletter Subscription

Sign up for our Computerworld newsletters!
Computerworld's twice-daily news service keeps you in touch with the latest, most important headlines from Australia and around the world.
Keep up with the latest virtualisation technologies, products, news and features.
RSS Feeds

Microsoft issued a critical patch for two vulnerabilities in the core graphics subsystem of Windows, one of eight fixes released Tuesday as part of its monthly security updates.

Microsoft released a total of five critical patches in its April security bulletin. Two of them fix bugs in Windows, two fix bugs in Windows and Internet Explorer (IE), and one fixes a vulnerability in Microsoft Office. The critical rating means an attacker could potentially exploit the flaws to hack into a victim's computer.

The other patches fix vulnerabilities in Windows and Office and were rated "important." Microsoft releases patches on the second Tuesday of every month, which has become known in the industry as "Patch Tuesday."

MS08-021 fixes two vulnerabilities in Windows' graphics device interface (GDI), one of three core Windows subsystems, that could allow a hacker to take over someone's computer if a user opens certain kinds of image files, according to Microsoft.

Eric Schultze, chief technology officer of security and patch-management company Shavlik Technologies, said the GDI patch is the most important because it fixes vulnerabilities that could create "a trifecta of problems" across all versions of Windows, from Windows 2000 to the latest Windows Server 2008 release. "If you visit an evil Web site, read an evil e-mail or open an evil document, you can get hacked," he said.

Schultze said the GDI issue has come up twice before, "dating back to January 2006," which means that this is Microsoft's third attempt at fixing the problems. "Hackers have come up with different variants" to attack the same vulnerabilities, he said.

Of the five patches marked critical, Schultze recommended that users also immediately install two others -- MS08-022, which affects Windows, and MS08-024, which affects both Windows and IE.

MS08-022 patches a vulnerability in VBScript and JScript scripting engines in Windows that originally was supposed to be patched in January, but Microsoft pulled the patch at the last minute because it wasn't ready, Schultze said. MS08-24 patches a vulnerability found in all versions of IE.

Amol Sarwate, manager of the Vulnerability Research Lab at security service provider Qualys, agreed that MS08-021 and MS08-022 are among the top three most important patches, but considers critical patch MS08-023 more important than MS08-022. MS08-023 fixes an ActiveX vulnerability that affects both Windows and Internet Explorer.

In Sarwate's opinion, MS08-021, MS08-022 and MS08-023 are especially important for users because they affect all versions of Windows, even if no other software is installed on the machine.

He also noted that because five of the eight patches affect both early client and server versions of Windows through the most current Windows Vista and Windows Server 2008 OSes, hackers are taking advantage of Microsoft's reuse of code throughout different versions of the OS.

The fifth critical patch, MS08-018, affects Microsoft Office, fixing a vulnerability that can be exploited when a user opens an Office Project file.

Computerworld Buyer's Guide - Vendors Matched to this Article
Market Place

Computerworld Member Login


 

Prioritizing Services with IT Service Management (ITSM)

Computerworld Live Webinar
Wednesday 20th, August 2008
11:00am EST (Sydney, Australia)

To be repeated on:

Thursday 4th, September 2008
11:00am EST (Sydney Australia)

Sign up and receive a free copy of The Forrester WaveTM Service Desk Management Tools, Q2 2008 at the conclusion of the Webinar.

Attend and discover:

  • How to deliver value to your business through ITSM
  • Best practice ITSM implementation
  • Why emphasis is changing from optimizing IT management processes to better servicing customers and demonstrating real dollar value
  • If service-oriented ITSM is best for your business
Whitepaper

Web Security SaaS: The Next Generation of Web Security

Discover the latest web security SaaS solutions. Learn how to increase overall security effectiveness and reduce the burden on your IT department. Uncover the security challenges facing SMB environments today and identify the critical elements that can provide you with lower-cost and easier-to-manage web security solutions.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links