Welcome | Sign In
ECommerceTimes.com
Security

Microsoft Light on Fixes This Patch Tuesday

Print Version
E-Mail Article
Reprints
Microsoft Light on Fixes This Patch Tuesday

Microsoft's fixes are few -- and most of them are merely "important" -- in the company's latest Patch Tuesday release. Still, security experts suggest users shouldn't be tempted to relax their vigilance. "What is important to remember is that most of these patches are based on code that has been out in the wild for some time," said Secure Computing VP Paul Henry.


How Much is 'Free' Costing You?
Learn how DaveRamsey.com saw a 567% uplift in ROI with Omniture. This complimentary guide and webinar cover the most important factors in selecting an analytics solution. Download Now.

Microsoft (Nasdaq: MSFT) has provided "important" updates for vulnerabilities in MSN Messenger, Windows Live Messenger and Windows Services for Unix 3.0 in its monthly Patch Tuesday release. Its most important fix -- a critical vulnerability -- is in its Windows Agent animation services. This is the agent that displays animated characters for internal use, such as the Microsoft Office "talking" paper clip.

While the number of fixes is relatively small, the vulnerabilities leave enterprises open to trouble in surprising ways, Paul Henry, vice president of technology evangelism for Secured Computing, told TechNewsWorld. With the Messenger issue, for example, "the code is out there in the wild, and the flaw allows a hacker to remotely execute code at the log-in user level."

MS07-054 -- Microsoft's fix to the zero day vulnerability in MSN Messenger -- belies its "important" status, remarked Amol Sarwate, manager of the vulnerability research lab at Qualys. If left unpatched, an MSN Messenger user's machine can become compromised simply by viewing a hacker's webcam.

"The MSN vulnerability comes on the heels of several recent new media attacks using social engineering to take advantage of end users," Sarwate said, "including a Yahoo (Nasdaq: YHOO) IM (instant messaging) webcam vulnerability patched with the release in July, as well as exploits based on graphics and video applications that popped up earlier this year."

Sarbox Violation?

Indeed, the potential for exposure is so widespread and so high that some firms consider it a possible violation of the Sarbanes-Oxley Act, Henry said.

By contrast, the one critical vulnerability, MS07-051, only affects Windows 2000 Service Pack 4 (SP4) users, not those running Windows 2003, XP or Vista operating systems, according to Sarwate.

A system can be compromised if a user browses to a malicious Web site.

Also labeled "important" by Microsoft is MS07-053, a Windows services for Unix patch for users who integrate Windows with Unix -- a relatively small universe.

One-Year Wait

Of more concern is MS07-052, which affects Crystal Reports files. "Social engineering tactics can be used here if a person is used to downloading an RPT file," Henry said.

Even savvy computer users are still falling prey to these tactics, he commented, especially as hackers stay one step ahead of the vendor patch rollouts.

"We are continuously seeing the bad guys alter their strategies based on what patches have been released," Henry said.

"What is important to remember is that most of these patches are based on code that has been out in the wild for some time," he observed. Indeed, the time between a patch release and the malware code's development is increasing -- it's now close to a year.


Print Version E-Mail Article Reprints More by Erika Morphy


More by Erika Morphy

Roku Channel Store Hangs Out Shingle
November 23, 2009
Roku's new channel store is based on a "one screen in the cloud" business model, said Michael Gartenberg, vice president of strategy and analysis with Interpret. "Essentially, what they are doing is taking the TV set -- whether it is a standard appliance or a high-def monster -- and enhancing it with content the consumer wants to see."
Ballmer Gives Shareholders - and Dell - Cause for Optimism
November 20, 2009
Microsoft CEO Steve Ballmer was all smiles at the company's shareholders meeting, as he touted the early success of Windows 7. Ballmer's cheer may have been contagious; after posting a massive earnings decline for the third quarter, Dell needed some good news to latch onto, and the prospect of broad enterprise adoption of Windows 7 could spur PC sales.
AA.com Sucks the Fun Out of Trip-Planning
November 20, 2009
Using AA.com to book a flight was a painful experience. Densely packed, disorganized information was displayed in an unattractive format. On the plus side, it did seem as though the deals American Airlines advertised were real and not mere bait-and-switch lures. For anyone who wants a travel-planning Web site to inject a little pleasure into the experience, though, I say look elsewhere.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network