Skip Links

Network World

Julie Bort

Microsoft's May Patch Tuesday: Tiny but potent

With just two security updates in May, industry watchers warn IT not to skimp on thoroughly patching their systems.

By Microsoft Subnet on Tue, 05/11/10 - 4:13pm.

It's not the quantity of the security updates issued by Microsoft on Patch Tuesday, but the quality, according to security industry watchers. Microsoft's May seemingly skimpy release of two security bulletins could give IT managers a false sense of security, especially considering one of the vulnerabilities could live on post-patching in third-party applications.

Microsoft goes small for next week's Patch Tuesday

"Since the big blast of patches in October, I think some of us have been desensitized by high bulletin numbers and pay less attention to updates that only address a couple of vulnerabilities," says Jason Miller, data and security team manager at Shavlik Technologies in Minneapolis. "Every time Microsoft rates a security bulletin critical, patching is also critical because these are potentially dangerous vulnerabilities."

Deemed critical by Microsoft, the security bulletin MS10-031 resolves a vulnerability in Microsoft Visual Basic for Applications, which could allow remote code execution "if a host application opens and passes a specially crafted file to the Visual Basic for Applications runtime," according to the company. That means an attacker could take control of the impacted system, Microsoft says. And industry watchers argue that another layer of risk is added on top of the vulnerability because this software from Microsoft is used in third-party applications from other vendors. And that means there may be a slew of patches coming out from third-party vendors that use Microsoft's Visual Basic for Applications in their products.

“I’ve put the Visual Basic for Applications vulnerability first on my list,” said Joshua Talbot, security intelligence manager at Symantec Security Response, in a statement. “The VBA vulnerability requires less action from a user. For instance, an attacker would simply have to convince a user to open a maliciously crafted file—likely an Office document—which supports VBA and the user’s machine would be compromised. I can see this being used in targeted attacks, which are on the rise.”

MS10-030 is the lesser of two evils with this month's bulletin, industry watchers agree. Still categorized as critical by Microsoft, the security bulletin addresses a vulnerability in Outlook Express, Windows Mail and Windows Live Mail - and could allow remote code execution if an end user visits a malicious e-mail server, according to Microsoft.

"It's possible that an attacker could somehow convince a user to do this - for example by enticing them to sign up for a new free mail service - but the steps required to do so would probably be a red flag for most users," Symantec's Talbot said.

Posted by Denise Dubie

Do you Tweet? Follow Denise Dubie on Twitter here.

Like this post? Check out these others.

Plus, visit the Microsoft Subnet web site for more news, blogs, podcasts. Subscribe to all Microsoft Subnet bloggers. Sign up for the bi-weekly Microsoft newsletter. (Click on News/Microsoft News Alert.)
Follow All Microsoft Subnet bloggers on Twitter
Follow Julie Bort on Twitter

What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
About The Microsoft Update

Julie BortJulie Bort is the editor of Microsoft Subnet and Network World's Online Community Editor. She also writes the Open Source Subnet blog and is the editor responsible for the Cisco Subnet and Open Source Subnet web sites. If you have an idea for a blog, or a news tip on Microsoft, Cisco or Open Source technologies, contact her at jbort@nww.com, 970-482-6454 or follow Julie on Twitter @Julie188.

The Microsoft Subnet blog is the official blog of the Network World's Microsoft Subnet community. Microsoft Subnet is the independent voice of Microsoft customers and is your gateway to daily Microsoft news, blogs, opinion, books, prize giveaways and more. Visit the Microsoft Subnet index page daily, and while you are there, subscribe to the Microsoft newsletter.

Become a Facebook Fan of Julie Bort

Policy on comments: Respectful discussion is welcomed! However comments that use inappropriate language, consist of name calling or personal attacks, or include accusations of wrongdoing are not appropriate. Those comments will be deleted or edited

 

Most Discussed Posts

Blog Roll
Microsoft Subnet Home Page
http://www.networkworld.com/subnets/microsoft/
All Microsoft Subnet bloggers
http://www.networkworld.com/community/blogs/microsoft/feed
ActiveWin
http://www.activewin.com
Blake Handler The Road to Know Where
http://bhandler.spaces.live.com/
Dmitry's PowerBlog
http://dmitrysotnikov.wordpress.com/
Doug Brown,DABCC
http://www.dabcc.com
Ed Bott's Windows Expertise
http://www.edbott.com/weblog/
Joseph Tartakoff Microsoft Blog
http://blog.seattlepi.nwsource.com/microsoft/
Long Zheng istartedsomething
http://www.istartedsomething.com/
Mini-Microsoft
http://minimsft.blogspot.com/
Paul Thurrott's Supersite for Windows
http://www.winsupersite.com
Robert McLaws WindowsNow
http://www.windows-now.com
Scobleizer
http://scobleizer.com/
Techmeme
http://www.techmeme.com/
Todd Bishop's Microsoft Blog
http://www.techflash.com/Microsoft