Size not everything on Patch Tuesday
By Miya Knights,
Late yesterday Microsoft patched six vulnerabilities in its software products with four patches related to Windows, Word, Publisher and its anti-virus software. Three patches were rated "critical".
Most analysts agreed the most important was a fix for Microsoft's Jet Database Engine, as they said last week in response to Microsoft's preview notice about May's round of regular security patches.
MS08-028 replaces components in Jet that Microsoft said could allow for remote code execution-based exploits if vulnerable Windows 2000, Windows XP SP2 and Windows Server SP1 systems become compromised.
Alan Bentley, Lumension (formerly PatchLink) Europe, Middle East and Africa regional vice president said: "The Jet bulletin is the critical patch that will have the widest impact because it affects Windows XP, Windows 2000 and Windows Server 2003. When prioritising this month's patches, this will probably get the most attention because of the number of organisations running these systems and programs."
The software giant only acknowledged that Jet - the Windows component that provides data access to applications such as Microsoft Access and Visual Basic - still had holes on 22 March. The company subsequently claimed it had remained unpatched for over two years, because it thought it had blocked the obvious attack vectors.
"Jet Database should be done first," suggested Amol Sarwate, Qualys vulnerability research lab manager. "This is a zero-day that Microsoft themselves acknowledged as having seen not only proof-of-concept code, but also public exploits."
The patch also took an unusual measure by changing some of the logic that allows Word documents to load Access .mdb files without prompting, following Microsoft's further admission in March that it had not anticipated this particular attack vector.
The bulletin added: "In addition to the changes that are listed in the 'Vulnerability Details' section of this [MS08-028] bulletin, this update includes logic enhancements to security warnings that mitigate Word as an attack vector used to exploit vulnerabilities in Microsoft Jet Database Engine. After applying this update, Word will prompt a user for confirmation before running SQL commands or queries when opening Word documents."
MS08-026 patched two critical bugs in Word and Outlook's rendering of rich text format (RTF) files and documents with cascading style sheets (CSS).
The patch was given the highest "critical" rating in Word 2000 and Outlook 2007 and rated as "important" in Word 2002, 2003 and 2007, as well as in the versions of Word included with Office 2004 for Mac and Office 2008 for Mac. Meanwhile, MS08-027 addressed a remote code execution flaw rated 'critical' and found in several versions of Microsoft Publisher.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Security Analysis & Insight
What is your password worth?
Would you be tempted to sell off company passwords for a fee? If not, seems like you're in the minority, acccording to research.
- Macs under attack?
- Intel: security inside
- Are you spending too much on IT security?
- Does the government want to snoop on your data?
- Eurocrats versus the cyber criminals
- The truth about spam
- Google and privacy: What’s the problem?
- Q&A: Symantec’s CISO on the source code hack
- RSA: Back from the breach?
Latest Security Reviews
Check Point 2210 Appliance review
Rating: ![]()
advertisement
Most popular
- Apple iPad 3 vs iPad 2 head-to-head review
- ICO: Fines for cookie law breakers
- Hutchison denies it will pull plug on Three UK
- Sony Vaio T13 Ultrabook review: First look
- BlackBerry 7 OS certified to carry 'Restricted' UK government information
- Facebook floatation marred by Nasdaq glitch
- Open source software driving cloud-based innovation
- CIO: Career is over?
- EMC World 2012: Tucci declares Documentum is here to stay
- Dell PowerEdge R820 review
Latest News Videos in Security
IT PRO Podcast: Are UK data protection laws flawed?
We bring in two experts to talk about the problems with UK data protection law and the way it is managed.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.





