Microsoft delivers monster security update for Windows, IE
Experts urge everyone to patch SMB bug pronto before hackers release another Conficker-style worm
Computerworld - Microsoft today patched a record 64 vulnerabilities in Windows, Office, Internet Explorer (IE), and other software, including 30 bugs in the Windows kernel device driver and one in IE that was exploited at the Pwn2Own hacking contest last month.
The company also delivered a long-discussed "backport" to Office 2003 and Office 2007 that brings one of the newer security features in Office 2010 to the older editions.
The 17 updates, which Microsoft dubs "bulletins," tied a record set late last year, but easily beat the October 2010 mark for the total number of flaws they fixed. Altogether, today's updates patched 64 vulnerabilities, 15 more than in October and 24 more than in the former second-place collection of December 2010.
Nine of the 17 bulletins were pegged "critical," Microsoft's highest threat ranking, while the remainder were marked "important," the next-most-serious label.
Microsoft and virtually every security expert pegged several updates that users should download and install immediately.
"There are three we think are top priorities," said Jerry Bryant, group manager with the Microsoft Security Response Center (MSRC), in an interview earlier today. Bryant tagged MS11-018, MS11-019 and MS11-020 as the ASAP updates.
MS11-018 patched five vulnerabilities in IE, three of them critical, including one that was used by Irish researcher Stephen Fewer to hack IE8 last month at the Pwn2Own contest, where he walked away with a check for $15,000 and a new notebook.
"We encourage customers to put this at the top of the list," said Bryant, "because we're seeing limited and targeted attacks using the Pwn2Own vulnerability."
Microsoft acknowledged those attacks yesterday in a tweet from the MSRC.
It's likely that the IE bug exploited at Pwn2Own made its way into the wild because others uncovered the same bug Fewer used at the hacking contest: HP TippingPoint, Pwn2Own's sponsor, does not divulge information about the bugs it buys.
"We often see multiple people finding the same bug," said Andrew Storms, director of security operations at nCircle Security.
The other bulletin that made its way to the top of everyone's list was MS11-020, which patched a critical vulnerability in Windows's handling of the SMB (Server Message Block) protocol.
"This is an old-school vulnerability, something that we haven't seen for a long time," said Amol Sarwate, the manager of Qualys' vulnerability research lab. "No user interaction is required to trigger this, and once inside, a worm using this could spread throughout the network."
Storms, who like Sarwate also ranked the SMB update alongside the IE bulletin, pointed out that the Conficker worm exploited a nearly identical bug.
Conficker, which began hitting Windows PCs in November 2008, infected millions of machines in the next few months, and caused a media frenzy in April 2009 when the massive collection of compromised computers was to receive a new malware update, also exploited an SMB flaw.
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Inquiry Spotlight: Consumer-Facing Identity The challenges of consumer-facing identity management, access management, and authentication differ in ways subtle and dramatic from those of the employee-facing variety.
- IDC Security Infographic From the Era Before security to this current era of empowerment this infographic from Blue coat provides a timeline navigates the rise of...
- Key Drivers: Why CIOs Believe Empowered Users Set the Agenda for Enterprise Security Several years ago, a transformation in IT began to take place; a transformation from an IT-centric view of technology to a business-centric view...
- Security Empowers Business Every magazine article, presentation or blog about the topic seems to start the same way: trying to scare the living daylights out of...
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Security White Papers | Webcasts
Rising salaries boost IT optimism, though not everyone is feeling upbeat. Our survey of 4,000+ IT workers shows who's riding the wave and why. Use our interactive tool and compare your own paycheck. Read more...