Pixalo Photography Community  

Go Back   Pixalo Photography Community > Photography Forums > Computer hardware, software, networking and internet
Register Search Today's Posts Mark Forums Read

Computer hardware, software, networking and internet Discuss Microsoft Issues Big Load For Patch...Windows users will be busy updating their machines this month. Microsoft's second Patch Tuesday of 2008 resulted in whopping ...

Welcome to the Pixalo Photography Community. As a Guest you are free to browse the site, but see what extras you get as a Member here.


Reply
 
LinkBack Thread Tools Display Modes
Old 13-02-2008, 03:50   #1 (permalink)
Feet under the table
 
j sotelo's Avatar
 
Join Date: Nov 2006
Location: San Diego, Ca. Where the Surf meets the Turf
Posts: 1,719
j sotelo is a glorious beacon of lightj sotelo is a glorious beacon of lightj sotelo is a glorious beacon of light
j sotelo is a glorious beacon of light

Image editing O.K.
User's Gallery
Users Camera Equipment List
Microsoft Issues Big Load For Patch

Windows users will be busy updating their machines this month. Microsoft's second Patch Tuesday of 2008 resulted in whopping 11 updates -- six critical and five important -- making this month's batch the biggest update load since August of last year.

The six critical updates patched numerous vulnerabilities in applications that had tremendous global usage, including WebDAV Mini-Redirector, OLE Automation, Microsoft Word, Internet Explorer, Microsoft Office and Microsoft Office Publisher. All critical patches protects users' machines from remote exploitation that could allow an attacker to take complete control or shut down an affected system.

While this month's round of patches fixed numerous serious errors, security researchers contend that in particular the most severe vulnerability fixed today was in the WebDAV Minidirector, a default Windows program installed automatically on user PCs. Unlike other critical vulnerabilities, a remote attack could be executed with elevated privileges, regardless of the end users' authentication status. The attacker could then infiltrate the affected machine to install programs, view, change or delete data or create new accounts.

"No matter who you're logged in as, the attacker will have system privileges on your machine," said Ben Greenbaum, senior research manager for Symantec Security Response.

In addition, Greenbaum underscored the seriousness of the cumulative Internet Explorer updates, which resolved a total of four vulnerabilities. The most serious of these errors could allow a remote attacker to execute malicious code by enticing users to view a specially crafted Web page using IE. Users with diminished privileged accounts or those with fewer system rights will likely be less affected than those accessing the browser with administrative privileges.

The popular browser has become an increasingly susceptible vector to exploits targeting Web 2.0, experts say. Greenbaum said that client side vulnerabilities have "gone through the roof" as applications continually become the focus of attackers' activities and as social engineering tricks become progressively more sophisticated.

"It's the way attackers are installing bot software to build a botnet," said Greenbaum.

The five patches given an "important" rating fixed holes in widespread applications that include Active Directory, Windows TCP/IP, Internet Information Services and Microsoft Works File Converter. Two of these patches for IIS and Microsoft Works File Converter fixed vulnerabilities that could be remotely exploited with malicious code.

The heavy update load came in direct contrast to January's relatively light release which contained just two fixes. Security experts maintain that Microsoft tends to alternate between heavy and light security bulletins. "We were somewhat due for something a little heavier," said Greenbaum.

Experts advise that users install all patches as soon as possible, due to the severe nature of the vulnerabilities. In addition, researchers recommend that users run as many programs as possible with decreased privileges, so as not to transfer those same privileges to potential attackers. "You should not be using IE on an administrator level account," said Greenbaum.

The security bulletin release contained one less update than expected. The Advanced Notification bulletin published Thursday of last week originally projected a total of 12 updates. A disclaimer on Microsoft's Web site noted that as last minute research is conducted, the bulletins may be pulled if researchers feel there "is an issue" with the update or if it fails to meet high enough quality protection standards.






taken from crn.com
__________________
"Man who fishes in other man's well often catches crabs" Chinese Proverb
j sotelo is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Microsoft issues emergency fixes for Vista orangepeel Computer hardware, software, networking and internet 7 10-08-2007 08:50
Patch Tool - A simple guide Rob Barron Tutorials and Guides 10 01-04-2007 10:31
Microsoft fixes flawed bug patch Pixalo Computer hardware, software, networking and internet 2 25-08-2006 12:10
Microsoft Announces new Photography File Format; Microsoft Media Photo Steve News 0 30-05-2006 14:25
New Patch for Windows Boon General Chat 26 07-01-2006 13:38

All times are GMT +1. The time now is 22:48.


vBulletin Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
ReviewPost & PhotoPost vB3 Enhanced, Copyright 2003-2006 All Enthusiast, Inc.
Content Relevant URLs by vBSEO 3.1.0
Copyright © 2006 - 2008 Pixalo.com

Loans | Advertising | Boston Moving Company | Credit Cards | Loans

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92