On TechRepublic: Linux desktops have tanked: Get over it
BNET Business Network:
BNET
TechRepublic
ZDNet

October 8th, 2009

Monster Patch Tuesday on tap: 13 bulletins, 34 vulnerabilities

Posted by Ryan Naraine @ 4:38 pm

Categories: Anti Virus, Arbitrary Code Execution, Browsers, Complex Attacks, Data theft, Denial of Service (DoS), Hackers, Kernel-level Exploits, Locally Running Web Servers, Microsoft, Passwords, Patch Watch, Pen testing

Tags: Monster, Vulnerability, Microsoft Corp., Microsoft IIS Server, Attack, Smb/Sme, Microsoft Windows, Security, Operating Systems, Software

Microsoft is planning a bumper Patch Tuesday next week — 13 bulletins covering 34 security vulnerabilities in a wide range of products. Eight of the 13 bulletins will be rated “critical,” Microsoft’s highest severity rating.

According to Microsoft’s advance notice, the patches coming on October 13 includes fixes for two serious issues that are well-known and already documented — a code execution bug in SMB v2 and a gaping hole in FTP in IIS.


Affected products include Microsoft Windows, Internet Explorer, Microsoft Office, Silverlight, Microsoft Forefront, Developer Tools, and SQL Server.

[ SEE: Microsoft confirms SMB2 vulnerability, warns of code execution risk ]

The most serious issue being addressed is the SMB v2 flaw that exposes users to remote code execution attacks.  Exploit code that provides a roadmap to launch attacks have been publicly released into the Metasploit Framework and into Immunity’s Canvas pen-testing platform.

Although only one documented issue is known, It appears Microsoft will be fixing multiple “vulnerabilities” in its implementation of the SMB v2 protocol.

[ SEE: Microsoft FTP in IIS vulnerability now under attack ]

The FTP in IIS vulnerability, first exposed in early September, is finally getting fixed.  That flaw, which affects IIS 5.0 (Windows 2000), IIS 5.1 (Windows XP) and IIS 6.0 (Windows Server 2003), has been under attack for a few weeks.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 52 Talkback(s)
Macs are popular in the states?
Actually, no, Macs are much more popular around
the world than they are "in the states". (Read the rest)
Posted by: goff256 Posted on: 10/13/09 You are currently: a Guest | | Terms of Use
Wow, FTP and SMBv2 vulnerabilities sound serious!!!  NonZealot | 10/08/09
Not that serious --  Bitzie | 10/08/09
Yeah, interesting to see Win7's track record so far  mechBgon | 10/08/09
That doesn't necessarily follow...  Zogg | 10/09/09
Lucky us...  MikeDevenney | 10/12/09
All software has bugs - it is foolish to think otherwise  Zogg | 10/13/09
Deja vu all over again  Chad_z | 10/12/09
SMBv2  honeymonster | 10/08/09
34 vulnerabilities - it IS that serious  terminalman | 10/11/09
Well...  zkiwi | 10/08/09
The tally?  odcchaz | 10/09/09
Considering a lot of those  Erroneous | 10/09/09
Yeah, same goes...  jasonp@... | 10/12/09
Wowsers...  DNSB | 10/12/09
RE: Monster Patch Tuesday on tap: 13 bulletins, 34 vulnerabilities  gertruded | 10/09/09
And you are sooooo predicatable...  Confused by religion | 10/09/09
Mine's not  UsersRevil | 10/11/09
This is no big deal.  Intellihence | 10/09/09
RE: Monster Patch Tuesday on tap: 13 bulletins, 34 vulnerabilities  Loverock Davidson | 10/09/09
Patch quantity  DNSB | 10/12/09
"Those who keep their auto updates on won't have anything to worry about."  ejhonda | 10/09/09
Firewall is enabled and blocking by default.  ye | 10/09/09
So your firewall means you won't have to install the critical patches?  whisperycat | 10/09/09
I made no such claim.  ye | 10/09/09
Et tu Brute...  jasonp@... | 10/12/09
A firewall can provide significant protection against many exploits  DevGuy_z | 10/09/09
How good is M$ firewall?  Agnostic_OS | 10/09/09
All ports closed, as expected  mechBgon | 10/09/09
Why the wait every month?  modernape2 | 10/09/09
The reason why -  whisperycat | 10/10/09
Ummm, exploits aren't viruses dude  mechBgon | 10/10/09
Uhh, Viruses are exploits too, dude  whisperycat | 10/11/09
*sigh* Viruses aren't exploits, dude. Srsly.  mechBgon | 10/11/09
Ahhh, the subtleties of the English language...  jasonp@... | 10/12/09
What?  mechBgon | 10/12/09
I wasn't talking about anti-virus updates  modernape2 | 10/12/09
RE: Monster Patch Tuesday on tap: 13 bulletins, 34 vulnerabilities  Diane84 | 10/09/09
Test your system and show the results...  Agnostic_OS | 10/09/09
I'll play - with my Mac.  whisperycat | 10/10/09
LOL, brilliant test  mechBgon | 10/10/09
Flooring your 'flaw'  whisperycat | 10/11/09
Don't quit the day job, then wink  mechBgon | 10/11/09
Not quite true...  DNSB | 10/12/09
So exactly why are you here then, to sell Macs?  UsersRevil | 10/11/09
But then...  SHNZ | 10/13/09
Lucky power user - shame about the millions of 'normal' WIndows users  whisperycat | 10/10/09
With Windows XP, you are right  Lerianis10 | 10/11/09
Ummm....  DNSB | 10/12/09
Mac Users and all alike!  chaz15 | 10/12/09
Macs are popular in the states?  goff256 | 10/13/09
RE: Monster Patch Tuesday on tap: 13 bulletins, 34 vulnerabilities  GregO.AppZero | 10/12/09
RE: Monster Patch Tuesday on tap: 13 bulletins, 34 vulnerabilities  davekingsb@... | 10/13/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here