Microsoft releases four "critical" security updates
By Rene Millman,
Microsoft has released four "critical" security updates to fix vulnerabilities in Windows and its Content Management Server software.
As reported by IT PRO, Microsoft has already rolled out an out-of-cycle emergency patch to fix a bug hackers could exploit in Windows' animated cursor handling process.
One patch fixes a privilege escalation vulnerability in the Microsoft Client/Server Runtime Server Subsystem (CSRSS) and affects all operating system versions, including Vista.
Another flaw in the Microsoft Agent URL Parsing Vulnerability could allow an attacker run arbitrary code as the currently logged in user.
"If the user is logged in as administrator, the result could be complete system compromise," said David McKinney at IT security company Symantec. "Therefore, Symantec recommends that tasks such as surfing the web be performed as a non-administrative user."
Another vulnerability in Universal Plug and Play could allow remote code execution. This memory corruption vulnerability is related to how HTTP requests to UPnP services are andled. Attacks using this vulnerability would have to originate from the same subnet as the vulnerable computer, according to Microsoft.
A memory corruption vulnerability in Microsoft's Content Management Server product could allow hackers to run remote code in the context of the IIS webserver. Microsoft considers this to be less of a threat for servers hosting Content Management Server with IIS 6.0 because the IIS service runs with the limited privileges of the Network Service account.
Another patch, rated "important", fixes a flaw in the Windows kernel that could also allow privilege escalation attacks by hackers.
As usual the scheduled update included the latest version of the Windows Malicious Software Removal Tool. There were also several on-security related fixes including refinements to Windows Mail in the way it identifies junk e-mail and grammar updates for some foreign-language versions of Vista.
Experts said that with the early release of one patch Microsoft is listening to its customers and responding to them rather than sticking to its own agenda.
"Clearly, the out-of-band patch is the worst of the bunch and should take priority over the others," said Alan Bentley, Managing Director of PatchLink. "When Microsoft feels a patch is important enough to release outside of the normal schedule, it should be taken very seriously."
He added that since all five critical patches are for remote code execution, which is often a vehicle for botnets and other targeted attacks, "it is essential that organisations remediate these vulnerabilities quickly."
Bentley said that IT administrators need to be aware of patches that are being released from other vendors.
"Just deploying Microsoft patches is not enough, organisations need to ensure every IT asset is inventoried, patched and compliant with applicable policy in order to best protect their network."
advertisement
Latest Security Features
How to be a successful online fraudster
Ever wanted to know how easy it is to be an identity thief and earn a fortune? IT PRO reveals all…
- What you need to know about ID cards
- Lessons to learn from a year of data breaches
- Q&A: DNS inventor Paul Mockapetris
- Is the password ill-equipped for the modern world?
- Why is backing up given short shrift?
- Defending Europe against cyber attack
- The present and future of IT security
- I’m an IT manager, get me out of here!
- IT around the world: Russia
Latest Security Reviews
Fortinet FortiGate-3810A
Rating: ![]()
- Clearswift MIMEsweeper Web Appliance ENW
- NetASQ U6000 UTM appliance
- AVG Internet Security SBS Edition 8.0
- Finjan Vital Security Web Appliance NG-6000S
- LogLogic MX2010
- Exclusive: WatchGuard Firebox Core X750e
- Sophos ES4000 Security Appliance
- Microsoft Forefront Security for Exchange and SharePoint
- EXCLUSIVE: Juniper Networks SSG 550 UTM appliance
advertisement
Latest News Videos in Security
Video: Eugene Kaspersky outlines security threats
IT PRO speaks to Eugene Kaspersky, chief executive and founder of Kaspersky Lab.
White papers
Want more background on today's hottest IT trends?
Visit IT PRO's white paper library for more on virtualisation, encryption and other topics.
Register for IT PRO
You'll get exclusive member benefits including free white papers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.



Social Bookmark this article: What is this?