Google Search

Showing posts with label including. Show all posts
Showing posts with label including. Show all posts

Wednesday, October 9, 2013

Microsoft announces five Bulletins for Patch Tuesday, including Office for Mac

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Midsummer Patch Tuesday (or midwinter, depending on your latitude) takes place on Tuesday 11 June 2013.

As you probably already know, Microsoft publishes an official Advance Notification each month to give you early warning of what's coming.

These early notifications generally don't give any details, summarising only the basics, such as:

The number of Bulletins (read: security patches) you'll get.The severity levels (read: urgency) of the patches.The products or components being fixed.Whether a reboot is required.

And June's answers, as briefly as possible, are:

Five.One critical and four important.Windows and Office.Yes.

So it sounds on the surface like a light month, with only two remote code execution (RCE) vulnerabilies to worry about.

Take note, however, that Microsoft's Affected Software chart states that one of the RCEs is a vulnerability in Internet Explorer 6 to Internet Explorer 10, on platforms from Windows XP right up to Windows 8 and Windows RT.

That makes it a risk to almost every Windows user out there.

The other RCE, which isn't rated critical, affects Office.

Interestingly, the versions at risk seem to be Office 2003 for Windows, and Office 2011 for Mac, meaning that this isn't just a Windows Patch Tuesday.

? As usual, Server Core installations aren't affected by the vulnerability in Internet Explorer (nor by the hole in Office), because Server Core deliberately omits the graphical components required to run GUI-based software like browsers, file viewers and word processors. You won't get caught out by surprise on Server Core when you visit a website, look at an image, or open a risky PDF file - for the compellingly simple reason that, by design, you can't do any of those things. We recommend that you use Server Core whenever technically possible.

There's also an update dealing with an elevation-of-privilege (EoP) flaw listed as being simply in "Windows."

The burning question is whether this fix deals with a vulnerability in the Windows kernel recently disclosed by Google researcher Tavis Ormandy, who published a working exploit on the Full Disclosure mailing list about three weeks ago.

Ormandy's initial Full Disclosure post appeared on 17 May 2013, noting that he had found a potentially exploitable vulnerability and asking for help to turn the bug into a working exploit.

Three days later, he'd solved his own problem and published what he claimed to be working exploit for all supported versions of Windows.

Note that EoPs don't always get critical ratings because they're often local exploits that can't be triggered remotely.

In such cases, you have to land before you can expand: you need to break into your victim's computer first, for example by using an RCE, and then use the EoP to "promote" yourself to administrator level.

Of course, if you're able to pull off an RCE in the first place, you can still infect your victim and wreak plenty of havoc, because malware doesn't need root-level access to log keystrokes, steal files, send spam and much more.

But an RCE followed by an EoP makes everything much worse, since any malware you unleash can do much more harm, such as altering system services, sucking data out of memory belonging to other processes, and even manipulating the operating system kernel itself.

So, watch this space (and the SophosLabs Vulnerabilities page) on Tuesday to find out exactly what's been fixed this month.

Follow @duckblog


View the original article here

Friday, May 17, 2013

Microsoft to patch security vulnerabilities on Tuesday - including some rated as "critical"

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Patch Tuesday is bringing seven security fixes, with Microsoft deeming four of them "drop-everything-and-fix-this-now" critical.

The patches are for Windows, Internet Explorer and Office, as well as a sprinkling for Windows Server and Silverlight.

Microsoft says that four of the patches will address "critical" vulnerabilities.

Emergency. Image from Shutterstock

"Critical" is, of course, Microsoft's highest severity rating.

It covers self-propagating malware such as network worms or common-use scenarios in which code is executed without warning or prompt, such as when users open booby-trapped email or suffer drive-by attacks from maliciously rigged webpages.

In this patch go-round, Microsoft warns that critical flaws might allow for remote code execution on Windows, IE, Silverlight and Office.

Another critical vulnerability would allow for elevation of privilege on Office and Server Software.

Flaws rated "important" could lead to elevation of user privileges or the disclosure of user data or personal information.

On Microsoft's vulnerability executive summary page, the company says that two of the patches address publicly disclosed holes - in Windows and Exchange Server.

MPEG iconOne of those two security updates, bulletin MS13-011, addresses a Windows vulnerability that would allow remote code execution via a boobytrapped media file, such as an .mpg; an Office document, such as a .ppt file containing a rigged and embedded media file; or maliciously crafted streaming content.

Hackers exploiting that vulnerability could gain the same user rights as the current user.

Bulletin MS13-012, an update for the second publicly disclosed vulnerability, fixes a Microsoft Exchange Server WebReady Document Viewing hole that could also allow remote code execution.

The problem here is with the security context of the transcoding service on the Exchange server when a user previews a maliciously crafted file using Outlook Web App (OWA).

Of course, as soon as Tuesday comes, malicious hackers will be glued to their screens. They'll be checking out Microsoft's patches and will get to work on code to exploit computers whose owners or system administrators haven't patched, pronto.

As for the vulnerabilities that have been publicly disclosed, well, those attackers have that much more of a head-start.

This month, as with every Patch Tuesday, the longer you wait to apply the security patches, the more time attackers will have to finesse, and launch, their attacks.

So don't delay: patch as soon as possible.

On the surface of it, March doesn't look half as gnarly as the monster-sized 57 updates that Microsoft dumped on our doorsteps in February.

But numbers don't tell the whole story. For every corporation, every patch brings the possibility of conflicts.

So this week, tiptoe gently around the support people. Lord knows they'll be busy making sure the place stays afloat.

Follow @LisaVaas
Follow @NakedSecurity


View the original article here