Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Microsoft issues 12 patches, eight of them for 'critical' flaws

Monthly patch release seeks to plug a total of 16 security holes

February 8, 2005 12:00 PM ET

IDG News Service - On the same day that it announced a deal to acquire antivirus software vendor Sybari Software Inc., Microsoft Corp. today released a total of 12 software patches designed to fix 16 vulnerabilities in Windows, Office and other products.
Eight of the new patches are for "critical" security holes that could be used to run malicious code on affected computers, Microsoft said. The group of fixes represents one of the largest single-day releases of software updates since Microsoft switched to a monthly patching approach in October 2003.
Microsoft provided patches for almost every supported version of Windows, including the recently issued Windows XP Service Pack 2. The company is trying to plug security holes in critical Windows components and in products such as its Internet Explorer Web browser and MSN Messenger instant messaging application.
The most serious problems that Microsoft is trying to address with this month's patch release include the following:


  • A vulnerability in a component of MSN Messenger that renders the Portable Network Graphics image files used to display icons, such as smiley faces. If the flaw is successfully exploited, malicious code could be hidden in a buddy icon and launched whenever MSN users load their IM contact lists, Microsoft said.

  • A flaw in the Server Message Block (SMB) protocol that affects Windows XP, Windows 2000 and Windows Server 2003 and could be used to launch attacks on vulnerable systems from Web pages. SMB is used to communicate between Windows machines and to share network resources such as printers and files.

  • A vulnerability in the License Logging Service (LLS) used in Windows Server 2003, Windows 2000 and Windows NT Server 4.0. The logging service is a tool that helps customers manage software licenses for Microsoft's server products. The company said a remote attacker could use the vulnerability to cause LLS to fail, creating the potential for denial-of-service attacks on systems running Windows Server 2003. Attackers could install programs; view, change or delete data; or create new user accounts on Windows 2000 and NT Server 4.0 systems, Microsoft added.

  • Four holes in Versions 5 and 6 of Internet Explorer. One of the patches includes a fix for a "drag and drop" vulnerability that could allow a remote attacker to use the Web to place an executable file on a Windows system without the user of the machine being shown a dialog box asking for approval for the download.

With the exception of the Internet Explorer holes, Microsoft doesn't know of any active attacks attempting to exploit the vulnerabilities, which were all discovered by securityresearchers outside of the company, said Stephen Toulouse, program manager at Microsoft's Security Response Center.
Microsoft recommends that companies assess their exposure to the vulnerabilities and make all applicable software patches as soon as possible, Toulouse said.
Aware of the burden being placed on IT security managers by the large number of patches, Microsoft also released an enterprise-level scanning tool designed to help users detect vulnerable computers. The new tool supplements the Microsoft Baseline Security Analyzer, according to Microsoft.
The company is also increasing the number of webcasts it holds to discuss deployment of the security updates, anticipating an increased need for help with this month's patch release, Toulouse said.

Reprinted with permission from

IDG.net
Story copyright 2009 International Data Group. All rights reserved.

Jump to comments

Security

Additional Resources

Xerox
By using solid ink technology only from Xerox, you could save up to 65% by printing color for the cost of black and white. Enter for a chance to WIN a PhaserTM 8860 network color printer!
Microsoft
Save time and mitigate security risk. Deploy it now.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

White Papers & Webcasts

Managing Secure File Transfer to Save Time, Money and IT Resources
Learn how companies are using innovative technology to overcome these challenges and improve user productivity by offloading e-mail attachments and replacing FTP with...

Can Heuristic Technology Help Your Company Fight Viruses?
What is Heuristic Technology and how can it help safeguard your business against viruses? Learn more.  

Security Convergence Equals Network Security Cost Savings
Listen to IBM Internet Security Systems' take on network security convergence.

Why Email Must Operate 24/7 and How to Make This Happen
Learn how to avoid an email outage by implementing a hosted email continuity solution.  

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...