On BNET: Dumb (but funny) career moves
BNET Business Network:
BNET
TechRepublic
ZDNet

October 13th, 2009

Patch Tuesday: MS plugs critical IE, Windows Media Player holes

Posted by Ryan Naraine @ 10:43 am

Categories: Anti Virus, Arbitrary Code Execution, Botnets, Browsers, Complex Attacks, Data theft, Denial of Service (DoS), Exploit code, Hackers, Malware, Metasploit, Microsoft, Patch Watch, Pen testing

Tags: Microsoft Windows Media Player, Windows Media, Vulnerability, Microsoft Windows, Microsoft Internet Explorer, Microsoft Corp., FTP, Microsoft IIS Server, Media Player, Security

Microsoft today released its largest ever batch of Patch Tuesday updates to fix a whopping 34 security holes in a wide range of widely deployed software products.

The latest patch batch covers critical vulnerabilities in software products that are bundled with Microsoft’s dominant Windows operating system (Internet Explorer and Windows Media Player) — and several known security problems (SMB v2 and FTP in IIS) for which functioning exploit code has already been publicly released.

The SMB v2 issue, which has been in the news over the last month, has been addressed with MS09-050, a critical bulletin that actually address three separate documented vulnerabilities.

The most severe of the vulnerabilities could allow remote code execution if an attacker sent a specially crafted SMB packet to a computer running the Server service. Firewall best practices and standard default firewall configurations can help protect networks from attacks that originate from outside the enterprise perimeter. Best practices recommend that systems that are connected to the Internet have a minimal number of ports exposed.

[ SEE: Microsoft FTP in IIS vulnerability now under attack ]

The second known issue, which has been exploited in the wild, is patched with MS09-053:

Two publicly disclosed vulnerabilities in the FTP Service in Microsoft Internet Information Services (IIS) 5.0, Microsoft Internet Information Services (IIS) 5.1, Microsoft Internet Information Services (IIS) 6.0, and Microsoft Internet Information Services (IIS) 7.0. On IIS 7.0, only FTP Service 6.0 is affected. The vulnerabilities could allow remote code execution (RCE) on systems running FTP Service on IIS 5.0, or denial of service (DoS) on systems running FTP Service on IIS 5.0, IIS 5.1, IIS 6.0 or IIS 7.0.

Microsoft also released a cumulative IE security update to fix four documented vulnerabilities that expose users to drive-by download attacks if an IE user is lured to a booby-trapped Web page.  These types of attacks are commonly used by cyber-criminals to load data-stealing Trojans on Windows machines.

A separate bulletin was also released to fix an ActiveX control vulnerability that is currently being exploited.   This issue is related to the security problems that have haunted programs compiled with the Microsoft Active Template Library (ATL).

The 13 bulletins released for October 2009 also fixes multiple ATL-releated vulnerabilities and a trio of holes in Microsoft .NET Framework and Microsoft Silverlight.

The vulnerabilities could allow remote code execution on a client system if a user views a specially crafted Web page using a Web browser that can run XAML Browser Applications (XBAPs) or Silverlight applications, or if an attacker succeeds in persuading a user to run a specially crafted Microsoft .NET application.

…The vulnerabilities could also allow remote code execution on a server system running IIS, if that server allows processing ASP.NET pages and an attacker succeeds in uploading a specially crafted ASP.NET page to that server and executing it, as could be the case in a Web hosting scenario.

See this page for more details on this month’s updates, including information on Microsoft’s exploitability index for each vulnerability.

This chart from Microsoft’s security response team (click image for full size) provides a visual representation of the severity of each vulnerability:

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 103 Talkback(s)
@sjaak327: Well, if your grammar and spelling is any indication
I can see why you would think Microsoft code is quality. ... (Read the rest)
Posted by: 914four Posted on: 10/20/09 You are currently: a Guest | | Terms of Use
Is MS going to pay for my Gb/month overage?  kd5auq | 10/13/09
Master Joe Says...  MasterJoe | 10/13/09
No offense? "Your an Idiot"?  RS9 | 10/13/09
No offense taken.  kd5auq | 10/13/09
Master Joe Says...  MasterJoe | 10/13/09
On this Vista SP2 system the total size...  ye | 10/13/09
And for Win7, it was 8.1MB  mechBgon | 10/13/09
WSUS  seannj427 | 10/14/09
RE: Patch Tuesday: MS plugs critical IE, Windows Media Player holes  lefty.crupps | 10/13/09
GOOD JOB!  RazorEdge | 10/13/09
34 patches and how many patch fixes?  RS9 | 10/13/09
Examples?  mechBgon | 10/13/09
MS patch  prof123 | 10/13/09
This OS  honeymonster | 10/13/09
Do you  athynz | 10/14/09
Guess you didn't get the memo...  SpikeyMike | 10/14/09
Good point, what was I thinking?  mechBgon | 10/13/09
First the stock price has been stagnant for a lot longer...  PollyProteus | 10/13/09
MS patches...  prof123 | 10/13/09
solid as a rock  rtk | 10/13/09
Headline knowledge serves no one  macadam | 10/14/09
.net coder ..  sjaak327 | 10/13/09
Odd that you associate...  zkiwi | 10/13/09
@ zkiwi  PlayFair | 10/14/09
Well, no doubt you've heard of "shared source"  zkiwi | 10/14/09
@sjaak327: Well, if your grammar and spelling is any indication  914four | 10/20/09
idk  avatoin | 10/14/09
Show me  honeymonster | 10/13/09
MS patches  prof123 | 10/13/09
Patch Tuesdays are 1/month, sir  mechBgon | 10/13/09
Patch tuesday  honeymonster | 10/13/09
Ok, I take that back...  prof123 | 10/13/09
Linux patches can be misleading.  pfyearwood | 10/13/09
Linux kernel  honeymonster | 10/13/09
Counting...  jeremychappell | 10/14/09
I call B.S.!  SpikeyMike | 10/14/09
Nice try  honeymonster | 10/14/09
The IBM FUD report again...  Wintel BSOD | 10/14/09
You need to update your OS!  windozefreak | 10/14/09
That's right!  Wintel BSOD | 10/14/09
You forget (or don't know)  anothercanuck | 10/14/09
A quick search shows that...  PollyProteus | 10/13/09
"A broken OS that constantly needs surgery."  avatoin | 10/14/09
And on a different topic... Adobe Acrobat and Reader 9.2 security updates  mechBgon | 10/13/09
Acrobat 8,1,7 Too  PMC-CON | 10/13/09
RE: Patch Tuesday: MS plugs critical IE, Windows Media Player holes  strueb | 10/13/09
Maybe your systems use an in-house update server  mechBgon | 10/13/09
Do someone have pirated software?  windozefreak | 10/14/09
RE: Patch Tuesday: MS plugs critical IE, Windows Media Player holes  aceone29 | 10/13/09
chrome...  Ceridan | 10/13/09
Windows 7: NO critical patches this month; MS SDL pays off  honeymonster | 10/13/09
No patches for...  msalzberg | 10/13/09
They are patching Win7, yep  mechBgon | 10/13/09
He said no critical patches.  ye | 10/13/09
I thought the release date...  msalzberg | 10/13/09
October 22nd is general (public) availability.  rtk | 10/13/09
...and it was released to MSDN/Technet Plus  Wolfie2K3 | 10/14/09
Shhhh..Don't Tell that to some Apple users  bobiroc | 10/14/09
And since it's only Oct 15th, rtk...  Wintel BSOD | 10/14/09
But I was wrong  honeymonster | 10/13/09
I did the same thing once.  ye | 10/14/09
What!?! - You're wrong!?!  Wintel BSOD | 10/14/09
Nothing new here...  zkiwi | 10/13/09
Who and where?  ye | 10/13/09
So, you missed your own post on...  zkiwi | 10/13/09
Which post is that?  ye | 10/13/09
Anyone else...  NStalnecker | 10/13/09
RE: Patch Tuesday: MS plugs critical IE, Windows Media Player holes  crzygrmn | 10/13/09
Yeah  NStalnecker | 10/13/09
They said only a 'whopping 34 security holes" sad Dosen't the  lightingrod | 10/13/09
P.S. I'm sure glad my Apple doesn't have this cr*p all  lightingrod | 10/13/09
So far  honeymonster | 10/13/09
Well what's your point?  Wintel BSOD | 10/14/09
Security patch 2009-002 fixed 68 vulnerabilities  ye | 10/14/09
Many were Unix security issues  macgroover | 10/14/09
Irrelevant. They're shipped as part of OS X therefore...  ye | 10/14/09
you poor naive...  avatoin | 10/14/09
Hmmm, those thought-control implants work better than I thought  mechBgon | 10/13/09
Yes, they also count  honeymonster | 10/13/09
In House Testing  bobiroc | 10/14/09
Which way is the wind blowing Ryan?  kaninelupus | 10/14/09
Are these patches safe?  roni5000 | 10/14/09
Outstanding, stay on top of it MS  No_Ax_to_Grind | 10/14/09
Well the little Dutch boy...  Wintel BSOD | 10/14/09
You people trip me out  athynz | 10/14/09
You nailed it!  rupaa62 | 10/15/09
RE: Patch Tuesday: MS plugs critical IE, Windows Media Player holes  Mikie in Minni | 10/14/09
Doubtful  bobiroc | 10/14/09
UAC was no security measure. It was a huge Annoyance.  roni5000 | 10/14/09
Then you do not understand it's purpose  bobiroc | 10/14/09
UAC's purpose is...  mechBgon | 10/14/09
Sure they're settling down...  Wintel BSOD | 10/15/09
It's not turned off by default in Win7  mechBgon | 10/15/09
If my car had 34 patches it would look ugly and I'd be a terrible driver.  roni5000 | 10/14/09
Yeah  bobiroc | 10/14/09
Question on MS09-062  Steve_STR | 10/14/09
Indeed, OLE Preview Pane is vulnerable to MS09-062  Steve_STR | 10/15/09
Just an FYI, OLE is "object linking and embedding"  rtk | 10/15/09
Good catch. However...  Steve_STR | 10/15/09
RE: Patch Tuesday: MS plugs critical IE, Windows Media Player holes  ctchism@... | 10/15/09
My laptop is now unusable, not even safe-mode.  ctchism@... | 10/15/09
Would you elaborate on your statement?  mustangj36@... | 10/15/09
RE: Patch Tuesday: MS plugs critical IE, Windows Media Player holes  inkwell | 10/19/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here