Skip Links

Network World

Julie Bort

Microsoft fixes 26 security holes, warns on unpatched multi-vendor SSL vulnerability

Patch Tuesday whopper is full of surprises, including first Hyper-V-specific patch

By Microsoft Subnet on Tue, 02/09/10 - 3:18pm.

As expected, today's Patch Tuesday is a doozie. Microsoft released 13 bulletins to fix 26 vulnerabilities in Windows and Microsoft Office. This includes the first Hyper-V-specific patch. But wait, there's more. Microsoft also issued a security advisory (977377) over a publicly-known vulnerability in the Transport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols.

As an issue affecting an Internet standard, Microsoft says that the problem affects multiple vendors. Microsoft has not patched the problem, but has issued a warning and a workaround for a hole that could could allow spoofing in TLS/SSL. Microsoft says it is not aware of any attacks in the wild but is investigating. The workaround enables system administrators to disable TLS and SSL renegotiation functionality, but this could break a good many applications that rely on TLS or SSL.

The hole affects nearly every Windows version including Windows 7 and the Server Core version of Windows Server 2008 R2.

As for Patch Tuesday, of the 13 patches, five are rated critical, seven rated important and one rated moderate –11 bulletins affect Windows and 2 affect older versions of Microsoft Office.

Microsoft says that enterprise customers should prioritize and deploy MS10-006MS10-007MS10-008MS10-013, and MS10-015. These not only fix critical holes -- the ones most likely to give hacker high access -- but holes in which they think hackers already have exploit code in the works, or will soon. More details of each of those holes can be found on the Microsoft Security blog.

The Security blog didn't specifically call out MS10-010 , which appears to be the first Hyper-V-specific patch. This patch is rated important and fixes an attack that could result in denial of service. It affects both Windows Server 2008 Hyper-V and Windows Server 2008 R2 Hyper-V.

Microsoft says, "The vulnerability could allow denial of service if a malformed sequence of machine instructions is run by an authenticated user in one of the guest virtual machines hosted by the Hyper-V server. An attacker must have valid logon credentials and be able to log on locally into a guest virtual machine to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users."

A search of the Security Bulletin database, and of Securina's database revealed no other patches specifically for Hyper-V, so I have concluded that this is a first. Does it mean that fears over virtualization security have been validated?

Please note, that most of these patches will require Windows to restart. Here is the full list of links to the information on all of today's patches:

Bulletin Number
MS10-006
MS10-007
MS10-008
MS10-009
MS10-012
MS10-013
MS10-003
MS10-004
MS10-010
MS10-011
MS10-014
MS10-015
MS10-005

Microsoft also says that its the Malicious Software Removal Tool (MSRT) was updated to include Win32/Pushbot.

Like this post? Check out these others.

Plus, visit the Microsoft Subnet web site for more news, blogs, podcasts. Subscribe to all Microsoft Subnet bloggers. Sign up for the bi-weekly Microsoft newsletter. (Click on News/Microsoft News Alert.)
Follow All Microsoft Subnet bloggers on Twitter
Follow Julie Bort on Twitter

About The Microsoft Update

Julie BortJulie Bort is the editor of Microsoft Subnet and Network World's Online Community Editor. She also writes the Open Source Subnet blog and is the editor responsible for the Cisco Subnet and Open Source Subnet web sites. If you have an idea for a blog, or a news tip on Microsoft, Cisco or Open Source technologies, contact her at jbort@nww.com, 970-482-6454 or follow Julie on Twitter @Julie188.

The Microsoft Subnet blog is the official blog of the Network World's Microsoft Subnet community. Microsoft Subnet is the independent voice of Microsoft customers and is your gateway to daily Microsoft news, blogs, opinion, books, prize giveaways and more. Visit the Microsoft Subnet index page daily, and while you are there, subscribe to the Microsoft newsletter.

Become a Facebook Fan of Julie Bort

Policy on comments: Respectful discussion is welcomed! However comments that use inappropriate language, consist of name calling or personal attacks, or include accusations of wrongdoing are not appropriate. Those comments will be deleted or edited

 

Most Discussed Posts

Blog Roll
Microsoft Subnet Home Page
http://www.networkworld.com/subnets/microsoft/
All Microsoft Subnet bloggers
http://www.networkworld.com/community/blogs/microsoft/feed
ActiveWin
http://www.activewin.com
Blake Handler The Road to Know Where
http://bhandler.spaces.live.com/
Dmitry's PowerBlog
http://dmitrysotnikov.wordpress.com/
Doug Brown,DABCC
http://www.dabcc.com
Ed Bott's Windows Expertise
http://www.edbott.com/weblog/
Joseph Tartakoff Microsoft Blog
http://blog.seattlepi.nwsource.com/microsoft/
Long Zheng istartedsomething
http://www.istartedsomething.com/
Mini-Microsoft
http://minimsft.blogspot.com/
Paul Thurrott's Supersite for Windows
http://www.winsupersite.com
Robert McLaws WindowsNow
http://www.windows-now.com
Scobleizer
http://scobleizer.com/
Techmeme
http://www.techmeme.com/
Todd Bishop's Microsoft Blog
http://www.techflash.com/Microsoft