Read up on the latest ideas and technologies from companies that sell hardware, software and services. HillsBus Puts Wi-Fi & GPS On Board
Gold Coast Convention Centre shows the way with next-generation Cisco wireless LAN technology
An introduction to LTE
The Power behind Wireless Communications
Intelligent Supply Chain Solutions using RFID
MyNetFone & Powertec Launch Fax Service Over 3G Mobile Networks
Millimeter-Wave (MMW) :An Application and Technology Primer
Lodgian Standardizes on Smart Wi-Fi to Let Guests Get Connected Fast and Stay Connected Fast
Zones provide focussed content from Computerworld and leading technology partners.Newsletter Subscription
Microsoft on Thursday chalked in four security updates for next week that would fix vulnerabilities in Windows, SQL Server and Exchange Server.
All four were labeled "important," the company's second-highest ranking, even though one of the Windows updates will quash a bug that attackers could use to execute malicious code remotely. That kind of vulnerability has been regularly rated as "critical" by Microsoft in the past.
As is its practice for pre-patch notifications, Microsoft disclosed few details Thursday of next week's updates other than their severity ranking and the affected software.
"None of these were on my radar," admitted Andrew Storms, director of security operations at nCircle Network Security Inc. "I'm doing quite a bit of head scratching given the variety and interesting details [in the bulletins]."
One of the two Windows bulletins will patch Windows 2000 and Windows XP -- including the recently released XP Service Pack 3 (SP3) -- but not Windows Vista, while the second update slated for the client operating system will patch Vista, including Vista SP1, but not the older OSes.
The Vista bug caught Storms' eye because while Microsoft said it could result in remote code execution -- a description reserved for a serious vulnerability that could let hackers hijack a PC -- the company ranked it as important, not critical.
"I read that kind of bug as 'critical'," said Storms. "Microsoft seems to have stepped it up a notch," he said, noting that it appears the company is taking a harder line in defining "critical" flaws as only those that don't require any user action to be exploited.
Microsoft described both the SQL Server bug and the Exchange vulnerability as elevation of privilege flaws, and will provide patches for the former to Windows Server 2003, Server 2008, Windows 2000 and all still-supported versions of SQL Server, the company said. The Exchange update applies to both Exchange Server 2003 and the newer Exchange Server 2007.
The amount of detail Microsoft tucked into the pre-patch notification for the SQL Server and Exchange Server vulnerabilities puzzled Storms, who pointed out that Microsoft specified that the former's flaw affected both WMSDE, the SQL engine added to Windows clients, and WYukon, the engine within Windows server software. "I don't know whether this is a clue [about the vulnerability] or whether they're just being more promiscuous with information," Storms said.
It doesn't appear the Microsoft will be patching an Internet Explorer vulnerability first reported in 2006, but which returned to the limelight last month when security researcher Aviv Raff claimed that it could be combined with a bug in Apple Inc.'s Safari to pose a danger to users. At the end of May, Microsoft warned users of the blended threat, and recommended that people stop using Safari.
Apple patched Safari for Windows to quash the browser's so-called "carpet bomb" bug two weeks ago.
But Storms thought there was an outside chance that Microsoft would fix IE, even though it didn't explicitly label any of the prospective patches as intended for Internet Explorer. Last year, he said, Microsoft dealt with protocol handler bugs that could be exploited by attacks against IE by fixing Windows, not the browser.
The four security updates will be posted Tuesday, July 8, around 1 p.m. EDT.
Computerworld Member Login
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
Fortinet Debuts Data Theft Detection and Prevention Security Appliance 2008-10-08 17:00:00+10
Open Text Positioned in Leaders Quadrant in Top Analyst Firm’s Enterprise Content Management Industry Report 2008-10-08 16:34:00+10
Carbonite Australia launches local website - www.carbonite.com.au 2008-10-08 15:54:00+10
Mid-Comp’s Odyssey supply chain solution allows Sydney University students to do their home work 2008-10-08 15:11:00+10
AIIA Challenges the ICT Industry to Reduce Australia's Carbon Footprint 2008-10-08 12:16:00+10
Understanding Email Marketing: A Guide for SMBs
Email marketing is often viewed as a marketers silver bullet. If used effectively, email campaigns will provide strong results for a limited spend each and every time. Download this white paper to discover how email marketing can work for you and your business.











