Skip Links

Network World

Julie Bort

Why I'm ignoring my W7 warning messages and other Microsoft Patch Tuesday news

Microsoft will issue five patches to five 15 holes, none critical while the world deals with the SSL certificate mess.

By Microsoft Subnet on Thu, 09/08/11 - 6:39pm.

On Tuesday, Microsoft will release five updates to fix 15 vulnerabilities, none critical, as part of its routine Patch Tuesday security patches. "A welcome break from Microsoft while we deal with the growing SSL Certificate Issues," says Paul Henry, security and forensic analyst for Lumension. He extends a hearty thank you to Microsoft, though in truth Microsoft is following its usual pattern of a alternating light/heavy Patch Tuesdays. August was a big month in which Microsoft released 13 bulletins that fixed 22 vulnerabilities, two critical.

The patches will fix holes in Windows, Excel, SharePoint Server and Groove. Henry summarizes the patches as follows:

Bulletin 1 Important – Elevation of Privilege impacting Microsoft Windows 2003 and 2008
Bulletin 2 Important – Remote code execution impacting Microsoft Windows all platforms
Bulletin 3 Important - Remote code execution impacting Microsoft Office (including Mac) / Microsoft Server
Bulletin 4 Important - Remote code execution impacting Microsoft Office
Bulletin 5 Important - Elevation of Privilege impacting Microsoft Office / Microsoft Server

While the light Patch Tuesday may not be a gift from Microsoft, it is still a relief as IT professionals work on updating their own server certificates via the updates Microsoft released earlier this week. These revoke all DigiNotar certificates and others that are sub-CAs to DigiNotar, like Koninklijke Notariele Beroepsorganisatie CA and Stichting TTP Infos CA.

The hacked certificate mess promises to grow uglier, too. On Thursday, the hacker who claimed responsibility, he calls himself "Comodohacker," declared that he had also penetrated the networks of StartCom, an Israeli CA, and U.S.-based GlobalSign.

Sigh.

While Microsoft customers were worried that the faked certificates could lead the bad guys to distribute malware through faked Windows Update services, Microsoft reassured its customers that this isn't possible. "Attackers are not able to leverage a fraudulent Windows Update certificate to install malware via the Windows Update servers," said Jonathan Ness, an engineer with the Microsoft Security Response Center (MSRC), in a Sunday blog post. "The Windows Update client will only install binary payloads signed by the actual Microsoft root certificate, which is issued and secured by Microsoft."

I, for one, am reassured. But still, when I noticed on Wednesday a warning note from my Windows 7 Action Center telling me I had to solve two PC issues, I was surprised. One of them told me I needed to address a problem with Office. I wasn't having any problems with Microsoft Office.

Windows Update message
Click to enlarge image.

The other one told me I needed to fix a problem with Skype (again ... having no problems with it) and gave me a URL to click where I could read the Skype's Knowledge Base article.

Ok, I'm not seriously suggesting that the certificate mess is responsible for these warning notes from Action Center. All the same, I think I'll wait until Microsoft, Mozilla, Google and the other white hats have stopped Comodohacker before I click on those links ...

What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
About The Microsoft Update

Julie BortJulie Bort is the editor of Microsoft Subnet and Network World's Online Community Editor. She also writes the Open Source Subnet blog and is the editor responsible for the Cisco Subnet and Open Source Subnet web sites. If you have an idea for a blog, or a news tip on Microsoft, Cisco or Open Source technologies, contact her at jbort@nww.com, 970-482-6454 or follow Julie on Twitter @Julie188.

The Microsoft Subnet blog is the official blog of the Network World's Microsoft Subnet community. Microsoft Subnet is the independent voice of Microsoft customers and is your gateway to daily Microsoft news, blogs, opinion, books, prize giveaways and more. Visit the Microsoft Subnet index page daily, and while you are there, subscribe to the Microsoft newsletter.

Become a Facebook Fan of Julie Bort

Policy on comments: Respectful discussion is welcomed! However comments that use inappropriate language, consist of name calling or personal attacks, or include accusations of wrongdoing are not appropriate. Those comments will be deleted or edited

 

Most Discussed Posts

Blog Roll
Microsoft Subnet Home Page
http://www.networkworld.com/subnets/microsoft/
All Microsoft Subnet bloggers
http://www.networkworld.com/community/blogs/microsoft/feed
ActiveWin
http://www.activewin.com
Blake Handler The Road to Know Where
http://bhandler.spaces.live.com/
Dmitry's PowerBlog
http://dmitrysotnikov.wordpress.com/
Doug Brown,DABCC
http://www.dabcc.com
Ed Bott's Windows Expertise
http://www.edbott.com/weblog/
Joseph Tartakoff Microsoft Blog
http://blog.seattlepi.nwsource.com/microsoft/
Long Zheng istartedsomething
http://www.istartedsomething.com/
Mini-Microsoft
http://minimsft.blogspot.com/
Paul Thurrott's Supersite for Windows
http://www.winsupersite.com
Robert McLaws WindowsNow
http://www.windows-now.com
Scobleizer
http://scobleizer.com/
Techmeme
http://www.techmeme.com/
Todd Bishop's Microsoft Blog
http://www.techflash.com/Microsoft