Three critical Windows updates from Patch Tuesday
By Miya Knights,
Microsoft has released seven patches that address a total of 11 vulnerabilities - two critical for Windows and one for Internet Explorer that is being actively exploited - as part of its December patch bulletin for 2007.
Alan Bentley, regional vice president of Lumension Security (formerly PatchLink) said: "This December Patch Tuesday will be no holiday for IT administrators. Following a light November, organisations need to get to grips with seven patches this month."
Critical patch MS07-069 affects versions 5.01, 6.0 and 7.0 of Internet Explorer (IE) and version 7.0 in Vista could allow remote code execution when a user views a malicious webpage.
Microsoft said it knew of hackers already exploiting this flaw and that user accounts configured to have fewer rights could be less impacted than those who operate with administrative user rights.
Bentley said administrators must pay particular attention to MS07-069 because it affect the entire IE user community. "The patch addresses how IE frees up used memory and offers hackers control of PCs," he said. "It is vital that organisations deploy this patch as quickly as possible because it affects a larger number of users than is typical."
The other two critical patches for Windows - MS07-064 and MS07-068 - can allow a hacker to remotely execute code on the compromised PC. MS07-064 tackles vulnerabilities in Microsoft's runtime environment, DirectX can allow the hacker to install malicious programs as well as view, change, or delete data and create new accounts with full user rights.
"MS07-068 could prove particularly troublesome for Windows Media users, as just by clicking on a seemingly harmless video a user could hand over control of their PC to a hacker," said Bentley. "Unfortunately, Christmas is the time of year that people wind down and share videos with their family and friends. Users must immediately apply this patch to avoid falling foul of this vulnerability."
Rated 'important,' bulletin MS07-063 was singled out because it exploits a new security code vulnerability that debuted in Vista. The packet signing technology, Server Message Block Version 2 (SMBv2) that allows two Vista machines to securely talk to one another ensures that the system is only receiving packets from an authorised participant in the conversation. But the flaw allows the attack to spoof packets in order to remotely execute code.
The other important patches are MS07-065, which could allow an attacker to remotely code execute in Microsoft Windows or raise privilege rights in Windows XP.
MS07-066 exploits a flaw in the Windows kernel that could enable a hacker to take over control of a Windows system, including installing programs, viewing, changing or deleting data and even creating new accounts that have full privileges.
And MS07-067 addresses a Macrovision driver vulnerability that again could allow a hacker to gain complete system control.
advertisement
Latest Security Features
NHS IT - something to celebrate?
To mark the 60th anniversary of the NHS, IT PRO examines the massive IT overhaul at the health services giant.
- Q&A – Tom Ilube, head of Garlik
- Ten of the most infamous ‘black hat’ hackers
- USB Flash Disks: A modern day business curse?
- Creating a mobile data management policy
- Behind the scenes: Symantec's malware battle
- The rise of storage security
- Google Mail Security
- Demand for tougher data breach legislation
- An Audience with Bill Gates
Latest Security Reviews
Finjan Vital Security Web Appliance NG-6000S
Rating: ![]()
- LogLogic MX2010
- Exclusive: WatchGuard Firebox Core X750e
- Sophos ES4000 Security Appliance
- Microsoft Forefront Security for Exchange and SharePoint
- EXCLUSIVE: Juniper Networks SSG 550 UTM appliance
- EXCLUSIVE: Arbor Networks Peakflow X 3.7
- EXCLUSIVE: Check Point UTM-1 1050
- EXCLUSIVE: Finjan Vital Security NG-5100
- EXCLUSIVE: Astaro Security Gateway 120 Appliance
advertisement
Latest News Videos in Security
Video: Q&A with Richard Archdeacon, Symantec
IT PRO speaks to Richard Archdeacon, director, global services, at the information security software vendor Symantec.
White papers
Want more background on today's hottest IT trends?
Visit IT PRO's white paper library for more on virtualisation, encryption and other topics.
Register for IT PRO
You'll get exclusive member benefits including free white papers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.




Social Bookmark this article: What is this?