Skip Links

Network World

  • Social Web 
  • Email 
  • Close

(Comma separation for multiple addresses)
Your Message:

Microsoft Patch Tuesday has three on critical list

By John Fontana , Network World , 12/11/2007
  • Share/Email
  • Tweet This
  • Comment
  • Print

Microsoft Tuesday released two critical patches for Windows and one for Internet Explorer that is being actively exploited, according to Microsoft.

The releases were part of the company’s monthly Patch Tuesday.

Critical patch MS07-069 affects versions 5.01, 6.0 and 7.0 of Internet Explorer, including 7.0 in Vista, and could allow remote code execution when a user views a Web page. Microsoft said hackers are already exploiting this vulnerability.

“This is ‘view an evil Web page and get hacked,’ the code executes without the user having to do anything,”says Eric Schultze, CTO of Shavlik Technologies. Schultz says the Web page looks like it may provide streaming media but in the background it is installing back doors, trojans and other malicious software.

Microsoft said that users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

The other two critical patches for Windows -- MS07-064 and MS07-068 -- would allow a hacker to remotely execute code on the compromised PC. MS07-064, which addresses vulnerabilities in Microsoft DirectX, would allow the hacker to install programs; view, change, or delete data; and create new accounts with full user rights. In all, Microsoft released seven patches, the three critical ones and four rated important, that address a total of 11 vulnerabilities.

The patch that was conspicuously absent was one for the Web Proxy Autodiscovery Protocol (WPAD) vulnerability, which exploits an eight-year-old flaw in Windows that as brought to light again last month.

The flaw lets hackers exploit a proxy configuration service and hijack a user’s Web traffic.

Schultze said the critical flaws in the December patch cycle were typical of past critically rated flaws and contained nothing out of the ordinary.

Schultze added that MS07-063 was interesting because it exploits new security code that debuted in Vista. The vulnerability is in Server Message Block Version 2 (SMBv2), which is a packet signing technology that allows two Vista machines to securely talk to one another. The packet signing is to ensure that the system is only receiving packets from an authorized participant in the conversation.

The vulnerability allows the attack to spoof packets in order to remotely execute code.

The vulnerability is tough to exploit, according to Schultze, and he adds that is likely why it is rated important rather than critical.

The SMBv2 feature is turned off by default in the operating system so a user who deliberately turns it on to enhance security is actually making their system less secure.

“This is a brand-new feature built for Vista, it is new code, and it has a big flaw that was not caught in Microsoft’s security-vetting process,” Schultz says.

The other important patches are MS07-065, which could allow an attacker to remotely code execute in implementations on Microsoft Windows 2000, or elevation of privilege in implementations on Windows XP; MS07-066, which exploits a vulnerability in the Windows kernel and could allow an attacker to take complete control of a Windows system, including installing programs; viewing, changing or deleting data; or creating new accounts that have full privileges; and MS07-067, which addresses a vulnerability associated with the Macrovision driver when exploited could give a hacker complete control of the system.

  • Share/Email
  • Tweet This
  • Comment
  • Print

Comments (9)
Login
Forgot your account info?

RE: Microsoft Patch Tuesday has three on critical listBy Anthony Staines on December 12, 2007, 4:25 amIsn't it astonishing that an exploit which is being used in the wild, was not patched urgently? This illustrates Microsoft's contempt for their users and their lack...

Reply | Read entire comment

What better way to sell theBy Dan Good on December 12, 2007, 11:35 amWhat better way to sell the next OS (Fear of the lack of security). To be fair Microsoft can not test for every variable their systems will be deployed in, so in...

Reply | Read entire comment

MS patch 07-069 (KB942615)By Joe Auerbach on December 12, 2007, 11:43 pmAfter installing it on an XP SP2 machine, I started getting error messages when starting IE. In an MS forum, I saw a suggestion to remove it, which fixed the error...

Reply | Read entire comment

"back" to the AS/400By Don Rima on December 20, 2007, 2:00 pmDan, Some of us have never left the AS/400(iSeries/i5/System i - or whatever IBM is calling it next week) :) Guess we know a good thing when it just works...and...

Reply | Read entire comment

Why would you implement the least secure?By Mike C on December 20, 2007, 2:09 pmGranted they can't test for every variable and I think you have to seperate client from server issues. From 2003 to 2007 there were 134 Secunia issued advisories...

Reply | Read entire comment

DisagreeBy Jim on December 20, 2007, 2:51 pmDan, I disagree with your statement entirely. Microsoft is a big target with large customer base. Switch it around and Unix or Linux or whatever you choose...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed