ITPRO

Printed from www.itpro.co.uk

Register to receive our regular email newsletter at http://www.itpro.co.uk/registration.

The newsletter contains links to our latest IT news, product reviews, features and how-to guides, plus special offers and competitions.

Skip to navigation

    Light Patch Tuesday, but server flaws serious

Microsoft has only issued four “important” security patches this month, but security experts say half should be treated as critical.

By Miya Knights, 9 Jul 2008 at 11:49

Microsoft released only four “important” security patches as part of its July Patch Tuesday update late yesterday.

Although the fixes were comparatively fewer in number than previous Patch Tuesdays and they were all given only Microsoft’s second highest severity rating, security experts are still urging IT administrators not to become complacent.

Andrew Clarke, Lumension Security international senior vice president said: “This [Patch Tuesday] gives administrators some breathing room to get caught up and assess their overall security posture from a mitigation standpoint.”

Thesecurity bulletin addresses the software maker’s Windows operating system (OS) as well as, more seriously from the security experts’ point of view, its SQL and Exchange servers.

“Organisations should pay close attention to the two security updates that address Elevation of Privilege on Microsoft SQL Servers and Microsoft Exchange Servers,” said Clarke.

The elevation of privilege on these targets can easily negate the policy and enforcement efforts made in the provisioning and access management setup on these important systems. MS08-039 updates Exchange 2003 and 2007 with two patches and MS08-040 is a four-patch update for Microsoft’s SQL Server software.

Clarke said companies that depend heavily on SQL and Exchange servers to manage and key data should address these patches as a “critical” level security update, the highest rating Microsoft has.

“Both of these products can be high-value targets and these vulnerabilities could be considered critical depending on the organisation,” added Clarke. “Many corporations hold not only their basic business information, but also their customer or patient data and critical intellectual property in Microsoft SQL Servers databases, or transmit these types of data via Microsoft Exchange servers.”

The third of the last two updates, MS08-038, addressed a remote code vulnerability in Windows Vista and Windows Server 2008 that affects the saved search feature and its associated file format in those OSs.

And MS08-037, patches two domain name system (DNS) bugs in every supported version of Windows except Vista. This “indicates the possible violation of the fundamental principle of trusted communication over the network and should also be seriously reviewed,” said Clarke.

“This threat affects most Windows platforms and could allow for the execution of spoofing attacks. Every network-based communication or transaction is based on trust between the sender and receiver," he added. "If that trust can be broken by mimicking a trusted source, then this becomes a major problem that needs to be closely examined and quickly addressed."

Email to a friend

Print this page

Social Bookmark this article: What is this?

Be the first to comment on this article

You need to Login or Register to comment.

advertisement
advertisement

    Latest News Videos in Security

Video: Q&A with Richard Archdeacon, Symantec

Play Video: Q&A with Richard Archdeacon, Symantec   Play

IT PRO speaks to Richard Archdeacon, director, global services, at the information security software vendor Symantec.

 

    White papers

Want more background on today's hottest IT trends?

Visit IT PRO's white paper library for more on virtualisation, encryption and other topics.

    Register for IT PRO

You'll get exclusive member benefits including free white papers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.

Sponsored results

  • BBC NEWS | dot.life | A blog about technology from BBC News | Xbox Live goes limp fault to a certain point, but take some own responsibilityI paid for the year, but I will use it when myhave got back connected but absolutley no...
    http://www.bbc.co.uk/blogs/technology/2008/01/x...
Advertisement