Microsoft rushes patches to fix 'big deal' programming flaw
Developers who used the buggy code 'library' must redo software, update customers
Computerworld - As promised, Microsoft Corp. today patched six vulnerabilities in Internet Explorer and Visual Studio with the first "out-of-cycle" update since last October, when it plugged a hole that the Conficker worm later used to run rampant.
Microsoft has been working on the Visual Studio bugs, and coordinating with third-party developers who may have crafted vulnerable software using Visual Studio, since early 2008.
As some had speculated, Microsoft rushed the patches to users this week to preempt a presentation slated for tomorrow at Black Hat by several security researchers. The researchers plan to demonstrate a way for attackers to bypass the "kill-bit" defenses that Microsoft frequently deploys as a stop-gap measure for fixing bugs.
"We put this out of cycle because we have seen at least one attack using an ATL vulnerability," Mike Reavey, director of the Microsoft Security Response Center (MSRC), said in an interview today. "And there was more speculation and more details being released before Black Hat. We had the patches ready for broad release, so we decided to release them today."
Without the pressure from Black Hat, Microsoft would have waited until Aug. 11, when the company will issue its next regularly-scheduled security update.
The two emergency updates, MS09-034 and MS09-035, fixed three "critical" flaws in IE, added new defensive technology to the browser and patched three "moderate" bugs in Visual Studio.
But in an unusual reversal, Microsoft hinted -- and some researchers agreed -- that the moderate bugs might actually pose the more serious long-term threat. That's because the Visual Studio vulnerabilities are in a code "library," dubbed Active Template Library (ATL), that Microsoft and an unknown number of third-party developers used to create their own ActiveX controls and application components.
"ATL is a C++ library, and one that's pretty commonly used by developers," said Amol Sarwate, the manager of Qualys Inc.'s vulnerability research lab.
"This will be one of those where users are vulnerable from hackers much longer than the usual," added John Pescatore, an analyst at Gartner Inc. "This is a big deal. Microsoft may be fixing the underlying problem in ATL and pushing out this shielding thing that will protect users of IE, but there's no way of knowing how many applications or controls have this flaw baked into them."
"This is a complex issue, providing a comprehensive response to a library vulnerability," Reavey acknowledged. "Library issues are hard to deal with, and take a lot of collaboration to resolve them." That's because a library flaw affects not just the development platform -- in this case Visual Studio -- but can also creep into the resulting code written with that platform.
Security Alert
- 'Here you have' e-mail worm spreads quickly
- 'Here you have' e-mail worm spreads quickly
- NSF: Time for an Internet do-over
- Cloudmark DesktopOne Basic Stops Spam
- Report: RBS WorldPay hacker gets four years' probation
- After Google incident, Wi-Fi data collection goes on
- Apple matches Mozilla, patches DLL hijacking bug in Safari
- Symantec: Most hacking victims blame themselves
- ACLU, other groups sue U.S. over border laptop searches
- On the job
Security

- A Step By Step Guide For Growing Businesses: Filling In Security Gaps
- Part 3 of this 3-part white paper series looks at which controls are the best fit for your organization and the order that...
- A Step By Step Guide For Growing Businesses: Customizing The Security Essentials For Your Business
- This 3-part series paper is designed to help SMB companies address their security needs while remaining within in their budget. It sets out...
- A Three Stage Approach to Security
- This 3-part series paper is designed to help SMB companies address their security needs while remaining within in their budget. It sets out...
- Protect the Data: Best Practices for Security Policies
- Blogs. Twitter. Facebook. Technologies once thought to be solely for entertainment purposes are now at the forefront of business. With users blurring the...
- Secure Your Email Today: Free 30-Day Trial of Red Condor
- Sign up for a free 30-day trial of Red Condor and you'll receive a free copy of "Email Security Solutions" (Retail Value: $295),... All Security White Papers
- Desktop virtualization keys innovation drive
- View now.
- Survival Guide: Overcoming the Obstacles to Effective Risk Management
- This virtual meeting for IT managers and CIOs is based on a new IBM study. Senior Vice Presidents and a Chief Technology Officer...
- The Evolution of Managed File Transfer
- Managed file transfer has evolved greatly from its earliest meaning of scheduled FTP to today's meaning of complete file governance, including visibility, enforcement,...
- How to cut software management costs and avoid over-spending in the future
- View now!
- Get a $20 Amazon Gift Card - Just watch a Demo
- View now! All Security Webcasts