Microsoft releases only one security update this month
By Miya Knights,
Microsoft confirmed late yesterday it was releasing only the one update this month as part of its regular cycle of monthly security patches.
While administrators are likely to be kept busy by a bumper patch of Oracle updates previewed on Monday, the Windows operating system (OS) maker focused its attention on the threat posed by a potential denial-of-service (DoS) attack vector.
Andrew Clarke, senior international vice president, for security firm Lumension, commented: “After a heavy load of patches in December, IT administrators can kick off the New Year with a light load as Microsoft releases only one security update. The one critical update addresses vulnerability in Windows, which affects all supported Windows versions and may require system reboot.
“This should come as good news for IT administrators, especially after a mammoth December, where Microsoft released eight critical updates to fix 28 vulnerabilities.”
The update in this month’s security bulletin fixes three bugs in the Windows Server Message Block (SMB) file and print service. The update warned: “An attacker who successfully exploited these vulnerabilities could install programs; view, change, or delete data; or create new accounts with full user rights.”
The flaws have been given the highest security rating of ‘critical’ for those organisations running Windows 2000, XP and Windows Server 2003, but are rated ‘moderate’ for Vista and Windows Server 2008 users.
Even the beta version of Microsoft’s upcoming Windows 7 OS released last week is affected by one of the flaws. But its testers will have to wait for the next public release, as the software firm doesn’t address products still in development in its monthly security updates.
Nevertheless, Microsoft said it was unlikely hackers would use the flaw to write exploits that could install malware on an unpatched system.
But one exploit is already known that introduces a DoS attack after an unpatched Vista system crash. And Microsoft added in a blog posting yesterday that enterprise users should patch “SMB servers and domain controllers immediately, since a system DoS would have a high impact”.
It also released an updated version of its Malicious Software Removal Tool designed to eliminate a worm, known as ‘Downadup’ and ‘Conficker’ among other names, that has infected millions of PCs in the past few months.
Clarke said this month’s light bulletin should provide an opportunity to get their ‘housecleaning’ in order to kick off the 2009 security planning process.
“This means getting their vulnerability and patching program in place by ensuring all previous patches, both Microsoft and non-Microsoft, have been deployed across their environment,” he added.
He also highlighted the MS08-67 patch for the remote procedure call (RPC) vulnerability reported back in October 2008, because security experts are starting to see new variants appearing in the wild.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Desktop Software Analysis & Insight
Could the UK ever build a Facebook?
Inside the enterprise: Building a $100bn tech company is a tall order. But the UK could still boost its technology industry, argues one expert.
- The current state of desktop virtualisation
- Big data: analytics' pot of gold
- Q&A: Paul Coby, IT Director John Lewis
- Hi #SMW, will you be my friend?
- Transparency? What transparency?
- 2011: The year in news
- HP CEO Meg Whitman makes confident public debut
- HP PCs back on the menu with Dellish plans
- Thin clients aren’t the future – BYOD should be
Latest Desktop Software Reviews
Ubuntu 12.04 review
Rating: ![]()
- LibreOffice 3.5 review
- Ubuntu vs. Windows 7 on the business desktop
- Head to Head: Parallels Desktop 7 vs VMware Fusion 4
- Microsoft Windows 8 review: First Look
- Samsung Galaxy Tab 7.7 review: First Look
- Samsung Galaxy Note review: First Look
- Fujitsu ScanSnap N1800 review
- Head to Head: Mac OS X 10.7 Lion vs Windows 7
- Apple MacBook Air 13-inch 256GB Mid 2011
advertisement
Most popular
- Apple iPad 3 vs iPad 2 head-to-head review
- Dell EqualLogic PS6100XS review
- Chromebooks: What's gone wrong?
- ICO: Fines for cookie law breakers
- UK regulator shuts down Angry Birds scam
- Open source software driving cloud-based innovation
- Fujitsu targets enterprises with Android ICS tablet
- IBM bans use of Siri on iPhones
- Dell PowerEdge R820 review
- BlackBerry 7 OS certified to carry 'Restricted' UK government information
Latest News Videos in Desktop Software
Video: Hands-on with the new Sony S Series
We take a brief look at what the new S Series machine has to offer business users.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.





