ITPRO

Printed from www.itpro.co.uk

Register to receive our regular email newsletter at http://www.itpro.co.uk/reg/register.

The newsletter contains links to our latest IT news, product reviews, features and how-to guides, plus special offers and competitions.

Skip to navigation

    Microsoft patch tackles SQL bug

Microsoft has plugged SQL Server holes that it admitted to knowing about in December as part of four security updates released in its monthly bulletin.

By Miya Knights, 11 Feb 2009 at 11:28

Microsoft late yesterday released four security updates, addressing a known SQL bug, as well as other email and browser software flaws.

Two of the bulletin’s four updates were given Microsoft’s highest 'critical' security rating. The two others, relating to its SQL Server and Visio technical drawing products, were rated 'important'.

The critical Exchange patch addresses a vulnerability that could allow hackers to shut down or gain remote control of an Exchange email server by sending a specially crafted email attachment.

According to security vendor TippingPoint, the Exchange patch should be given the highest priority. "A compromised email server, in addition to snooping corporate secrets, can be used as a launch pad for attacks against other servers in the enterprise,” it said.

The second critical update, for Internet Explorer, plugs two holes that Microsoft said could be used to run unauthorised software on a victim's computer. The flaw relies on the user visiting a webpage containing malware, although no attacks have yet been seen to exploit it.

The long-awaited SQL Server patch fixes a bug in the database software that Microsoft acknowledged last December, despite the fact that it has been aware of it since its discovery last April by a researcher.

Yesterday’s update replaces the initial patch Microsoft produced to address the SQL bug in September. The software firm said the flaw could also allow hackers to gain unauthorised access to unpatched systems.

Email to a friend

Print this page

< Previous   Security : News Next >

1 comments

You need to Login or Register to comment.

Microsoft will announce soon about dotDefender

If you all ready got hit with sql injection attacks on your server you will need to download a software call dotdefender - its will make sure that your attacks will decrease significantly.

By Daniel on Sunday Aug 16

1 people out of 1 found this comment useful.

Did you find it useful?

 Sponsored Links

advertisement
advertisement

    Register for IT PRO

You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.

Sponsored Links
Advertisement