On CHOW: Make your next sandwich perfect
BNET Business Network:
BNET
TechRepublic
ZDNet

October 9th, 2008

MS Patch Tuesday heads-up: 11 bulletins, 4 critical

Posted by Ryan Naraine @ 4:12 pm

Categories: Arbitrary Code Execution, Botnets, Browsers, Complex Attacks, Exploit code, Metasploit, Passwords, Patch Watch, Pen testing, Responsible disclosure, Windows Vista, Zero-day attacks

Tags: Vulnerability, Exploit Code, Microsoft Corp., Bulletin, Security, Ryan Naraine

11 bulletins, 4 criticalIt will be a very busy Patch Tuesday for administrators managing Microsoft Windows computer systems.

According to Microsoft’s advance notice mechanism, 11 security bulletins will drop next Tuesday (October 14, 2008), covering a wide range of serious vulnerabilities.

Four of the 11 bulletins are rated “critical,” meaning that those vulnerabilities can be exploited to launch remote, code execution attacks.


[ SEE: Microsoft makes daring vulnerability sharing move ]

The four “critical” bulletins apply to the widely deployed Internet Explorer browser, Active Directory, Microsoft Excel and Host Integration Server.

Six of the bulletins will be rated “important” and will provide fixes for a range of Microsoft Windows operating system vulnerabilities.

The final bulletin, rated “moderate,” will provide patches for an information disclosure bug in Microsoft Office.

This month will see the first appearance of the previously announced Exploitability Index, a new Microsoft initiative aimed at attempting predictions on whether exploit code will be released.

This index will attempt to predict if a vulnerability is likely to have functioning exploit code released, or have inconsistent exploit code released that wouldn’t work every time an attacker attempted to used it. We’ll even highlight vulnerabilities where we think it’s unlikely that functioning exploit code will ever be released.

Starting this month, Microsoft will also start sharing details on software vulnerabilities with security vendors ahead of Patch Tuesday under a new program aimed at reducing the window of exposure to hacker attacks.

The new Microsoft Active Protections Program (MAPP) will give anti-virus, intrusion prevention/detection and corporate network security vendors a headstart to add signatures and filters to protect against Microsoft software vulnerabilities.

* Image source: jeffwilcox’s Flickr photostream (Creative Commons 2.0)

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 4 Talkback(s)
What a Profound Comment
Truly, brilliant. Could you tell us your point. (Read the rest)
Posted by: greybeardtechie Posted on: 10/23/08 You are currently: a Guest | | Terms of Use
Funny...  Qbt | 10/10/08
Eeewww! There we go again !! (nt)  Gradius2 | 10/10/08
IE7 for Vista is rated Important, NOT critical !  qmlscycrajg | 10/13/08
What a Profound Comment  greybeardtechie | 10/23/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here