On last.fm: Michael Jackson radio - Listen now!
BNET Business Network:
BNET
TechRepublic
ZDNet

January 17th, 2008

Don't dawdle on Microsoft latest batch of patches

Posted by Larry Dignan @ 12:03 pm

Categories: Exploit code, Microsoft, Patch Watch, Viruses and Worms, Vulnerability research, Windows Vista

Tags: Patch Management, Immunity, Microsoft Corp., Worm Attack, Ryan, Stewart, Cyberthreats, Patches, Security, Viruses And Worms

If you’re like most folks you are taking your time installing Microsoft’s latest round of security patches. However, you may want to get your rear end in gear.

Specifically apply MS08-001, which was released on Jan. 8. That patch fixed a Transmission Control Protocol/Internet Protocol (TCP/IP) processing vulnerability that was critical for XP and Vista.

The vulnerability if left unpatched could lead to a worm attack. Ryan Naraine interviews the hacker that brought the bug to Microsoft last August and the details are worrisome.

So how can this turn into a worm attack? Immunity has issued a proof of concept attack for the vulnerability (available to customers). It’s a just a matter of time before this code goes into the wild.

Ryan appears to be sold on the idea of a potential worm attack. I agree just based on odds–we haven’t been hit with a serious worm for two years.

Microsoft has noted that the latest flaw isn’t likely to lead to a worm attack in real-world conditions. Then again, Microsoft has spent some serious digital ink on its Security Vulnerability Research and Defense blog over MS08-001. “We think successful exploitation for remote code execution is not likely,” says Microsoft.

Is that a fact or a challenge? Hackers are likely to choose the latter.

Simply put, Microsoft didn’t have a lot of patches to kick off 2008, but the ones it delivered shouldn’t be ignored.

Naturally there are complications. The biggest one is that this patch may not be easy to install.

Holly Stewart at IBM ISS sums it up:

MS08-001 poses some unique problems from a remediation and protection standpoint. First of all, you have the update itself. It changes the core TCP/IP driver, and does so for a very good reason. If you don’t already know the severity of CVE-2007-0069 patched in MS08-001, let me just say a few words here…

* affects all currently supported Microsoft operating systems
* on by default except on 2003 Server
* remotely exploitable
* requires no user interaction

This equals bad.

In addition, this patch may break your apps.

Stewart writes:

Although I’m sure Microsoft has quality standards way beyond my wildest QA department fantasy, and I know they have a huge lab and excellent program dedicated to interoperability, it is difficult to predict how driver changes will interact with everything. If I were a customer running a network with a lot of home-grown apps that tapped into network drivers, this update would scare the bejesus out of me.

Scary your not, you need to take this Microsoft patch batch seriously. That said, I don’t envy IT folks that have to implement this patch. Critical patch and broken apps could be ahead.

Larry DignanLarry Dignan is Editor in Chief of ZDNet and Editorial Director of ZDNet sister site TechRepublic. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 30 Talkback(s)
RE: Don't dawdle on Microsoft latest batch of patches
Sexxat.com - Instant Sex Social Networking is a new multi room and multi cam video chat site.
Using top level flash technologies, members can use free chat to communicate among each other, make use... (Read the rest)
Posted by: eathen Posted on: 10/21/08 You are currently: a Guest | | Terms of Use
I may have my gripes, but MS does keep up on security patches.  HypnoToad72 | 01/17/08
August to January isn't "keeping up" with ANYTHING  critic-at-arms | 01/19/08
After a recent patch killed the connection between...  Mr. Roboto | 01/17/08
I'm in the mon-ey, I'm in the mon-ey  Chad_z | 01/18/08
Bull  No_Ax_to_Grind | 01/18/08
I can't quite figure out which one...  bjbrock | 01/18/08
Agreed!  DevGuy_z | 01/18/08
Too easy!!  techboy_z | 01/18/08
Message has been deleted.  itanalyst | 01/18/08
Dude, calm down.  James T. Kirk | 01/18/08
deleted again!  jeanruss | 01/18/08
OK, here are 2  The_Curmudgeon | 01/18/08
Not sure just what broke..  DNSB | 01/18/08
Wrong side of the tech trend, buddy  Chad_z | 01/19/08
Answering this is like clubbing baby seals  critic-at-arms | 01/19/08
Well, I'm glad the patch is good for SOMEONE!  critic-at-arms | 01/19/08
The gap narrows  whisperycat | 01/18/08
Give us the full quote!  NonZealot | 01/18/08
Agreed  hollystewart | 01/18/08
Good reply, Holly...  JCitizen | 01/18/08
Bzzzt!  RocketEater | 01/18/08
Oops! I forgot that unit that has Office 2003..  JCitizen | 01/18/08
Great patch! It breaks the TCP/IP core.  The_Curmudgeon | 01/18/08
Now you know what they've been doing since August  critic-at-arms | 01/19/08
Re:  jnoooo | 01/20/08
Reply to "Linux isn't better  joe.smetona@... | 01/28/08
100,000 or so would disagree.  joe.smetona@... | 01/28/08
Latest patches  cohens@... | 01/18/08
beware of kb943485 (ms08-002)  pcdoc33@... | 01/18/08
RE: Don't dawdle on Microsoft latest batch of patches  eathen | 10/21/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More