Microsoft delivers monster security update for Windows, IE
Experts urge everyone to patch SMB bug pronto before hackers release another Conficker-style worm
Computerworld - Microsoft today patched a record 64 vulnerabilities in Windows, Office, Internet Explorer (IE), and other software, including 30 bugs in the Windows kernel device driver and one in IE that was exploited at the Pwn2Own hacking contest last month.
The company also delivered a long-discussed "backport" to Office 2003 and Office 2007 that brings one of the newer security features in Office 2010 to the older editions.
The 17 updates, which Microsoft dubs "bulletins," tied a record set late last year, but easily beat the October 2010 mark for the total number of flaws they fixed. Altogether, today's updates patched 64 vulnerabilities, 15 more than in October and 24 more than in the former second-place collection of December 2010.
Nine of the 17 bulletins were pegged "critical," Microsoft's highest threat ranking, while the remainder were marked "important," the next-most-serious label.
Microsoft and virtually every security expert pegged several updates that users should download and install immediately.
"There are three we think are top priorities," said Jerry Bryant, group manager with the Microsoft Security Response Center (MSRC), in an interview earlier today. Bryant tagged MS11-018, MS11-019 and MS11-020 as the ASAP updates.
MS11-018 patched five vulnerabilities in IE, three of them critical, including one that was used by Irish researcher Stephen Fewer to hack IE8 last month at the Pwn2Own contest, where he walked away with a check for $15,000 and a new notebook.
"We encourage customers to put this at the top of the list," said Bryant, "because we're seeing limited and targeted attacks using the Pwn2Own vulnerability."
Microsoft acknowledged those attacks yesterday in a tweet from the MSRC.
It's likely that the IE bug exploited at Pwn2Own made its way into the wild because others uncovered the same bug Fewer used at the hacking contest: HP TippingPoint, Pwn2Own's sponsor, does not divulge information about the bugs it buys.
"We often see multiple people finding the same bug," said Andrew Storms, director of security operations at nCircle Security.
The other bulletin that made its way to the top of everyone's list was MS11-020, which patched a critical vulnerability in Windows's handling of the SMB (Server Message Block) protocol.
"This is an old-school vulnerability, something that we haven't seen for a long time," said Amol Sarwate, the manager of Qualys' vulnerability research lab. "No user interaction is required to trigger this, and once inside, a worm using this could spread throughout the network."
Storms, who like Sarwate also ranked the SMB update alongside the IE bulletin, pointed out that the Conficker worm exploited a nearly identical bug.
Conficker, which began hitting Windows PCs in November 2008, infected millions of machines in the next few months, and caused a media frenzy in April 2009 when the massive collection of compromised computers was to receive a new malware update, also exploited an SMB flaw.
- Silicon Valley's 19 Coolest Places to Work
- Is Windows 8 Development Worth the Trouble?
- 8 Books Every IT Leader Should Read This Year
- 10 Hot Hadoop Startups to Watch
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- Radicati: Cloud Business Email - Market Quadrant 2013 Google was named the top cloud business email provider in a recent report by research firm Radicati. Out of 14 key players, Google...
- Tablets in the Enterprise: A Checklist for Successful Deployment How can you enterprise manage and secure tablets in order to protect corporate data while providing access to the information and applications employees...
- Enterprise Mobility: A Checklist for Secure Containerization The advantages and disadvantages of the multiple approaches to containerization. Learn More>>
- Enterprise File Sync & Share Checklist File sync and share has changed the way people work and collaborate in today's tech-savvy world. Gone are the email roadblocks, clunky FTP...
- Live Webcast Best Practices: How to Improve Business Continuity with Virtualization VMware solutions include a range of business continuity capabilities to help ensure availability for applications across your virtualized environment. Learn More>>
- Live Webcast LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- Live Webcast
Enhance Your Virtualization Infrastructure With IBM and Vmware
Date: Wednesday, May 14, 2014, 1:00 PM EDT
Virtualization technology is now expanding beyond the server compute elements to encompass networking and storage...
- LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy... All Security White Papers | Webcasts