Google Search

Showing posts with label issue. Show all posts
Showing posts with label issue. Show all posts

Wednesday, June 19, 2013

Microsoft to issue 9 security updates on Tuesday, critical for all IE versions, reboot required

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Microsoft has issued its routine advance notification for the coming week's Patch Tuesday.

As usual, the "pre-announcement" is a bit like a bikini: interesting more for what it conceals than what it reveals.

Nevertheless, there's enough to make sure you're ready for Tuesday 09 April 2013 (or Wednesday, of course, if you live at the longitude of about Thailand or further east).

This month's nine updates don't sound too onerous, with just two at critical level and the remaining seven important, but the critical ones affect Internet Explorer (IE) and Windows itself, and the IE fix will require a reboot.

Just so you know.

Importantly, the IE update applies to all supported versions of the browser, from IE 6 to IE 10, on all supported version of Windows, from XP and Server 2003 to Eight and Server 2012, in both 32-bit and 64-bit flavours.

Server Core installs, happily, aren't affected by either of the two critical flaws.

? Internet Explorer isn't part of a Core install, which doesn't support GUI applications for safety's sake. This reduces your attack surface area tremendously and you should go for a Server Core installation whenever you can.

As you may have seen, there has been plenty of speculation that the critical updates will include patches for the IE vulnerabilities exploited in the recent PWN2OWN competition.

Mozilla and Google triumphantly rushed out patches to the holes in Firefox and Chrome that were found at PWN2OWN, closing down the vulnerabilities within 24 hours.

As we remarked at the time, this certainly threw down the patching gauntlet to Microsoft, though we also pointed out that:

Redmond, to be fair, has many more products with much more complex inter-relationships to juggle than Mozilla, and even Google.

With the PWN2OWN rules this year requiring responsible disclosure, meaning that winners had to reveal their attacks to the affected vendors and allow time for a considered and tested fix, it wasn't actually necessary for Microsoft to rush.

If Redmond's security team does fix IE's PWN2OWN bugs on its offical April patch day, it will in my opinion have done a timely job, but until Tuesday, Microsoft is keeping the details up its sleeve.

Note that five of the non-critical patches fix what's known as elevation of privilege, a trick that allows untrusted software to do things beyond its official authority.

Usually, that means a program running as a regular user can complete operations that would normally require administrator privileges, such as modifying system settings or altering critical files,

As you can imagine, attackers often combine RCE, or remote code execution, with EoP, or elevation of privilege.

They use the RCE to escape from the strictures of your browser, or some other interactive application, and then the EoP to escape from the limitations of your regular login account.

Either sort of exploit is dangerous on its own, but together they are much more harmful.

So plan to patch all the holes, not just the critical ones, and watch out on Naked Security and the SophosLabs Vulnerabilities page for our analysis and assessment of the updates once we're clear to publish.

(We have to wait until Microsoft has made the updates live before we give away any details.)

Bonne chance!

Follow @duckblog


View the original article here

Sunday, May 20, 2012

Adobe's fix for Photoshop CS5 security issue? Buy Photoshop CS6

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Pay for a security update from AdobeWay to alienate a loyal customerbase, Adobe.

Earlier this week we reported on how users of a bunch of Adobe products, including Photoshop CS5 and earlier, were being warned about serious security issues.

In the case of the Windows and Mac versions of Adobe Photoshop, a vulnerability exists in version CS5 and earlier that could be exploited by a malicious attacker who tricks you into opening a boobytrapped .TIF file in order to take control of your computer.

That's a very serious problem. So, you would imagine that users would be rushing to download the security patch. Right?

Wrong.

Because the only fix that Adobe is making available is for users to upgrade to the latest version of Adobe Photoshop CS6. And that's going to cost users $199 or more. (If you aren't eligible for the upgrade, it will cost $600).

Ouch.

Adobe's advice - pay up

And it's a similar story for Windows and Mac users of Adobe Illustrator CS5.5 and earlier, and Adobe Flash Professional CS5.5 (11.5.1.349) and earlier. In each case, Adobe's answer is for you to pay a not inconsiderable amount of money to update to the next major version of the product in order to benefit from the security fix.

Sure enough, social networks and online forums are buzzing with posts from disgruntled users - angry that they are having to shell out hundreds of dollars for something which is, after all, Adobe's fault.

Photoshop upgradeAdobe meanwhile tells users to "exercise caution" over what files they open with their applications, if they aren't prepared to pay for the upgrade.

What a PR disaster for the company.

At first when I heard the news I thought there must be some mistake. Maybe Adobe's security advisories had been worded poorly and although upgrading - for example, to PhotoShop CS6 - would fix the vulnerability, the firm would also roll out a free patch to users of earlier versions.

But no. Judging by a report from H-Online, Adobe has no plans to publish a free security fix.

Adobe's view is that because Photoshop "has historically not been a target for attackers" the risk level doesn't make it worthwhile to produce a fix that users don't have to pay for.

Maybe Adobe customers who feel nervous opening .TIF files will judge the level of risk for themselves, and prefer to seek alternatives from companies that take better care of their users.

Follow @gcluley

View the original article here