Microsoft patches IE, Windows Media Player flaws
The seven security patches deal with 11 different flaws
IDG News Service - Microsoft Corp. has rolled out its monthly security updates for December, patching critical flaws in Internet Explorer, Windows Media Format and the Visual Studio 2005 development software.
The seven security patches address 11 bugs, including two in its Windows Media Player software. However, no fixes were provided for two Microsoft World flaws that have been used in a small number of attacks over the past week.
Microsoft had said it would release only six patches on Tuesday, but the company added the Windows Media Format update at the last minute, after reports of attacks based on this vulnerability began surfacing. The Windows Media Format is used by Microsoft's Windows Media Player software.
In late November, security vendors warned that a buffer overflow error could occur when the Windows Media Player processed ".asx" (Advanced Stream Redirector) media files, meaning that users would first need to be tricked into opening a malicious media file for the attack to work.
In its update today, Microsoft also patched a similar bug in the way the media player processes ".asf" (Advanced Systems Format) files.
The Internet Explorer patch fixes four bugs. It is also rated critical and is noteworthy because some of these bugs will probably begin to be exploited by hackers by week's end, said Gunter Ollmann, director of IBM Internet Security Systems' X-Force threat analysis service.
Enterprise administrators should also pay close attention to an Simple Network Monitoring Protocol (SNMP) patch, Ollmann said.
Microsoft has rated this patch as "important," rather than critical because SNMP is normally blocked at the firewall and turned off by default on Windows systems. However, it is widely deployed as part of the network monitoring infrastructure in the enterprise, and is often used on critical servers, Ollmann said.
Ollmann believes this SNMP patch is the "most important" update for enterprise customers.
"Since the service is widely deployed in the enterprise and since it's commonly deployed on servers, we think this would be an important attack vector for enterprises," he said.
The remaining updates include a "critical" fix for Visual Studio 2005, and "important" updates for Windows and Outlook Express, Microsoft said.
Microsoft defines "critical" flaws as bugs that could allow the propagation of an Internet worm without any action on the part of the victim.
The company's next set of security updates is due Jan. 9.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
- Identity Governance: The Business Imperatives
- This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make... All Security White Papers
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Introduction to VMware vCenter Site Recovery Manager 5
- Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
- The Top Ten Secrets to Avoiding SAN Performance Problems
- Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
- Deduplication Without Compromise
- Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
- Director of Disk Products Discusses DXi6700
- Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts