On The Insider: Taylor Lautner Plays Beach Football
BNET Business Network:
BNET
TechRepublic
ZDNet

July 27th, 2009

Microsoft to ship emergency IE, Visual Studio patches

Posted by Ryan Naraine @ 6:18 am

Categories: Adobe, Arbitrary Code Execution, Botnets, Browsers, Complex Attacks, Data theft, Exploit code, Flash, Microsoft, Patch Watch, Pen testing, Research, Responsible disclosure, Vulnerability research, Zero-day attacks

Tags: Microsoft Visual Studio, Patch Management, ActiveX Control, Microsoft Internet Explorer, Microsoft Corp., Web Browsers, ActiveX/COM/COM+/DCOM, Internet, Software Development, Software/Web Development

Less than a month after a first pass at patching a troublesome flaw affecting its dominant Internet Explorer browser, Microsoft has announced plans to release two emergency updates with a comprehensive fix for the problem.

The unusual move comes on the heels of a bombshell blog post by reverse engineering specialist Halvar Flake that the original IE kill-bit fix was “insufficient” and that Microsoft “might have accidentally introduced security vulnerabilities into third-party products.”

Microsoft declined to discuss specifics of the emergency patches until tomorrow (July 28, 2009) but a source tells me that it is directly linked to the Microsoft Video ActiveX Control (msvidctl.dll) issue that was being exploited in the wild.

[ SEE: IE users beware: Zero-day attacks hit Microsoft Video ActiveX Control ]

Tomorrow’s out-of-band updates will address:

  • One bulletin will be for the Microsoft Visual Studio product line; application developers should be aware of updates available affecting certain types of applications.
  • The second bulletin contains defense-in-depth changes to Internet Explorer to address attack vectors related to the Visual Studio bulletin, as well as fixes for unrelated vulnerabilities that are rated Critical.

Interestingly, the issue of using kill-bits to secure IE from ActiveX control vulnerabilities will take center stage at the Black Hat security conference this year.  IBM X-Force researcher Mark Dowd will show how these kill-bits can be bypassed [video demo] to launch code execution attacks.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 112 Talkback(s)
I'nm using Vista SP2 on a cheapo
It came from Walmart. Seriously, did Vista rape you or something? (Read the rest)
Posted by: goff256 Posted on: 07/31/09 You are currently: a Guest | | Terms of Use
Why not patch it now  Randalllind | 07/27/09
Most likely testing.  ye | 07/27/09
Although MS should release two cycles..  JT82 | 07/27/09
I suspect they don't because a lot of exploits are derived from...  ye | 07/27/09
Well.....  todbran@... | 07/27/09
They didn't ask me either. And I like it. (nt)  ye | 07/27/09
You like anything M$  Wintel BSOD | 07/28/09
And you hate anything MSFT  goff256 | 07/29/09
Because you're doing it right now wink  Wintel BSOD | 07/29/09
I read, I observe...  goff256 | 07/29/09
It's not a matter of being cool  Wintel BSOD | 07/29/09
I'nm using Vista SP2 on a cheapo  goff256 | 07/31/09
msft is patching it now  jerryz58 | 07/28/09
People Still Use IE?????  itanalyst2@... | 07/27/09
Sure do. One of the most secure browsers to use..  ye | 07/27/09
Since most......  todbran@... | 07/27/09
Changes nothing about what I said. So no, not negated.  ye | 07/27/09
Hmmmmm....  KeithAu001 | 07/27/09
I Heard That!  zdnet-gregc | 07/27/09
You boys must be new here.  mgp3 | 07/27/09
Hear hear  jerryz58 | 07/28/09
OK, how's this.....  todbran@... | 07/27/09
Re: OK, how's this.....  neverhome | 07/27/09
You manage to run 3 computer repair centres..  eqpc | 07/28/09
Probably one like Geek Squad...  Marty R. Milette | 07/28/09
Hey...  Wintel BSOD | 07/28/09
wait hold up a second  JamesDoyle | 07/28/09
As we've said already...  scorchgeek | 07/28/09
You obviously are lying...  CrashPad | 07/28/09
How do you know?  Wintel BSOD | 07/28/09
negated  tmsbrdrs | 07/28/09
Vista sucks?  slofsjes@... | 07/28/09
Vista had issues out of the gate which are fixed now  Randalllind | 07/29/09
I run IE8 inside a Tab in Firefox When I HAVE to Use IT.  Seadaddy611 | 07/27/09
What "we" develop for  killroy42 | 07/28/09
Still Many Sites Are IE Only  EBathory | 07/29/09
ie in a tab?  zclayton3 | 07/28/09
Probably means uses FF add-on: IE tab  valvestate@... | 07/28/09
right behind...  wel51x | 07/27/09
"One of the most secure browsers to use..."  jacarter3 | 07/28/09
Such as?  ye | 07/28/09
I wasn't refuting what you wrote  jacarter3 | 07/28/09
What are your sources for that?  B.O.F.H. | 07/28/09
Ever heard of Secunia?...  JCitizen | 07/28/09
Only on state government sites  Randalllind | 07/27/09
Development  KeithAu001 | 07/27/09
TRUE!! Client side scripting is rarely needed!..(nt)  JCitizen | 07/28/09
Development Mk II  KeithAu001 | 07/27/09
good call...and:  NT-Services@... | 07/28/09
You realize you are just being naieve right?  JT82 | 07/28/09
based on your needs, perhaps...  NT-Services@... | 07/28/09
Vista x64 with IE8 has only one vulnerability...  JCitizen | 07/28/09
Good call...  Marty R. Milette | 07/28/09
Funny!..  JCitizen | 07/28/09
many sites use ActiveX, but  NT-Services@... | 07/28/09
Unfortunately.  James T. Kirk | 07/27/09
People Still Use IE?????  ICUR12 | 07/28/09
FINALLY  Timewellwasted | 07/28/09
You've proven a the old saying..  GetReal-mac.com | 07/28/09
Youre still breathing????  CrashPad | 07/28/09
RE: Microsoft to ship emergency IE, Visual Studio patches  atxchip | 07/27/09
really.....  mrdt | 07/27/09
Your experience isn't his  goff256 | 07/29/09
Easily 30%+ sites 'can't find server' - LOL... grin  Wintel BSOD | 07/28/09
True! And I was going to say...  JCitizen | 07/28/09
Dump IE8 too!  metilley@... | 07/27/09
Agree! Dump IE8  ericgrunewald@... | 07/27/09
IE-8  JohnPaulJones | 07/27/09
Uninstalling IE 8...  JCitizen | 07/28/09
Funny..  crypt2121 | 07/27/09
Hmm...  bishofthedump | 07/27/09
A little knowledge is a dangerous thing.  Timewellwasted | 07/28/09
Yet I find my self drawn back to the swill..  JCitizen | 07/28/09
Re: Dump IE8 too!  HowardH47 | 07/27/09
Re: Inspiron 1100...  metilley@... | 07/28/09
Hey! No problem!..  JCitizen | 07/28/09
yeah whatever....  CrashPad | 07/28/09
RE: Microsoft to ship emergency IE, Visual Studio patches  Ron406 | 07/27/09
RE: Microsoft to ship emergency IE, Visual Studio patches  gennx30 | 07/27/09
RE: Microsoft to ship emergency IE, Visual Studio patches  prof123 | 07/27/09
Please switch!  Marty R. Milette | 07/28/09
Umm...  scorchgeek | 07/28/09
RE: Microsoft to ship emergency IE, Visual Studio patches  charled56@... | 07/27/09
RE: Microsoft to ship emergency IE, Visual Studio patches  chrispy7 | 07/27/09
RE: Microsoft to ship emergency IE, Visual Studio patches  jmccardl2@... | 07/27/09
Why do you peole keep driving cars which need  lynne1462@... | 07/27/09
If incompetents set up...  Marty R. Milette | 07/28/09
Why do you people keep driving cars which need  blueskip | 07/28/09
RE: Microsoft to ship emergency IE, Visual Studio patches  dca@... | 07/27/09
RE: Microsoft to ship emergency IE, Visual Studio patches  WAB6 | 07/27/09
You're outnumbered...  Marty R. Milette | 07/28/09
I think it's more about...  Li1t | 07/28/09
I did switch to Linux  blueskip | 07/28/09
Blueskip,  mhenriday | 07/28/09
Come on DOJ...,  preacherx | 07/28/09
We're abolishing all browsers with defects?  goff256 | 07/29/09
If they just stopped ActiveX,  hkommedal | 07/30/09
RE: Microsoft might have accidentally introduced security vulnerabilities  NT-Services@... | 07/28/09
Sigh.  bendib | 07/28/09
sigh  nerak99 | 07/28/09
"irrational attitudes of submission to authority"?  valvestate@... | 07/28/09
RE: Microsoft to ship emergency IE, Visual Studio patches  joday | 07/28/09
IE7?  goff256 | 07/29/09
It's Tuesday and no patch for me  Randalllind | 07/28/09
They're available now.  ye | 07/28/09
what is the KB #?  Randalllind | 07/28/09
Now You Know Why  ebhb2004@... | 07/28/09
I was checking Windows Update for this blog  Randalllind | 07/28/09
Okay...  DannyO_0x98 | 07/29/09
If you don't update Windows, you are worse virus bait than ever  valvestate@... | 07/29/09
I think ....  Timothy (TRiG) | 07/29/09
You base it off of...  goff256 | 07/29/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here