news4geeks.net
15Feb/120

Microsoft quashes 21 bugs, blocks drive-by attacks

Microsoft today issued nine security updates that patched 21 vulnerabilities in Windows, Internet Explorer (IE), Office, .Net, Silverlight and SharePoint Server, including several critical bugs that can be exploited with drive-by attacks.

Four of the nine updates were labeled "critical," Microsoft's highest threat ranking; the others were marked "important." Of the 21 total vulnerabilities, Microsoft classified six as critical, 14 as important and one as "moderate," a step below important on the company's four-step rating system.

MS12-010, which included fixes for four vulnerabilities in Ie, and MS12-013, a one-patch update to Windows Vista, Windows 7, Server 2008 and Server 2008 R2, were unanimously selected by both Microsoft and independent security researchers as the two to deploy immediately.


Those two should need no prompting to reach the top of the patch list, said Jason Miller, VMware's manager of research and development. "Browsers and media files are the most sought-after for attackers because the audience is the biggest user base they can hit," said Miller.

Three of the four bugs addressed by MS12-010 can be exploited with "drive-by" attacks, the term that describes exploits that only require an IE user to be drawn to a malicious website to trigger the vulnerability.

MS12-008 patches a critical flaw in Microsoft's C Run-Time Library, a dynamic link library (dll) that ships with most versions of Windows, and is used by both Microsoft and third-party developers.

"MS12-013 looks quite nasty and ominous," said Andrew Storms, director of security research at nCircle Security. "But the Security Research & Defense blog brought our feet back to the ground by describing that the only way to exploit [the vulnerability] is through Windows Media Player," added Storms.

Attackers must convince victims to either download and open a malformed Media Player file, or visit a malicious website that hosts such a file, said Microsoft in the blog Storms referenced.

Miller wasn't so sanguine about MS12-013, betting that the Media Player attack vector would attract hackers.

"All an attack requires is that the user open a media file, and we know how prevalent media is now," said Miller. "An email with a malicious link may not be very interesting, but if you tell [the recipient] there's a video of something cool, they're much more likely to continue."

Microsoft today also patched vulnerabilities in Visio, a relatively little-used member of the Office family; in a Windows kernel-mode driver; in SharePoint Server; in the .Net and Silverlight frameworks; and in other products in its portfolio.

February's nine security updates can be downloaded and installed via the Microsoft Update and Windows Update services, as well as through Windows Server Update Services.

(Source: computerworld.com)

 

Linux marks 20th anniversary, recounts past slights from Microsoft
The mythical "year of the Linux desktop" still hasn't come, and may never, but on the 20th anniversary of Linux the free operating system's proponents threw a party ...
READ MORE
Microsoft conceals job ad in Bing homepage
Microsoft are looking for a new Bing developer - but you'll need to be pretty smart to apply. Oh, and you can only use Internet Explorer, which rules ...
READ MORE
Microsoft late Friday confirmed that a "zero-day," or unpatched, vulnerability exists in Internet Explorer 8 (IE8), the company's most popular browser. According to multiple security firms, the vulnerability ...
READ MORE
China's ZTE has become the latest firm to sign a licensing deal with Microsoft for its Android and Chrome patent portfolio. The firm, which is one of the world's biggest smartphone ...
READ MORE
Microsoft's current financial team has been laying out the company's future strategy, and is hoping that a new rash of smaller Windows 8 PCs and cloud revenues will ...
READ MORE
Linux marks 20th anniversary, recounts past slights from
Microsoft conceals job ad in Bing homepage
Microsoft admits zero-day bug in IE8, pledges patch
Microsoft hoists ZTE onto the Android patent bandwagon
Microsoft betting on smaller Windows 8 devices and

Comments (0) Trackbacks (0)

No comments yet.


Leave a comment

Trackbacks are disabled.