Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Microsoft ships six critical patches, but two lesser vulnerabilities could be killers

When combined, two vulnerabilities rated important can have critical consequences for Web servers.
By John Fontana , NetworkWorld.com , 02/12/2008

Microsoft Tuesday released 11 security patches, six with the highest rating of "critical" that span Windows, Office, and Internet Explorer, but some say it is a combination of two non-critical vulnerabilities that should catch the eye of corporate IT.

Of the six critical vulnerabilities, none of them require any more user interaction than opening a document or visiting a malicious Web site. All six allow the attacker to take complete control of a user’s machine.

The vulnerabilities affecting Internet Explorer as part of bulletin MS08-010 are troubling, according to experts, because of the wide-spread use of both IE 6 and 7, which are both at risk. (Compare Patch and Vulnerability Management products.)

“In the past, a lot of the IE stuff has been around the scripting engines, but this is in the core HTML rendering engine,” says Don Leatham, director of solutions and strategy at Lumension Security.

Office, another widely used client, is vulnerable in critically rated patches MS08-008, 009, 012 and 013.

“I would tell my mom to install 010 first, but for corporate users they should install 006 and 005 first,” says Eric Schultze, CTO of Shavlik Technologies. He says MS08-005 and MS08-006, while rated important, can be viewed as critical vulnerabilities since they allow a hacker to gain control of a Web server and to escalate privileges from “user” to “admin.”

“With the combination of 006 and 005, I can remotely attack your Web site and become an administrator,” says Schultze. “Each one is rated ‘important,’ but I call them critical in both cases.”

“006 is back to the days of Code Red where you can execute code on a Web server,” says Schultze. “That means I can execute TFTP (Trivial File Transfer Protocol) and have TFTP come back to my machine and upload hacker tools. I can end up with a C prompt of your Web server. I can have shell access to your Web server as a user. I call that critical right away. I can install a port redirector on that system so I can attack other system in the DMZ and use the port redirector to bypass your firewalls and filtering rules.”

Shultze says the final dagger comes with patch 005.

“Combine that with 005, which allows a user of a Web server to become administrator of a Web server. So I just hacked you with 006 and now as a user I can run more code to become an admin.”

Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.

Download the white paper.

Unauthorized applications: Taking back control

Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?

Download the white paper.

Comments (1)
Login
Forgot your account info?

Killer Patch Tuesday with "important" patches a top priorityBy Microsoft Subnet on February 13, 2008, 10:26 amGood thing Microsoft gives users a month between each major update! This was one of the biggest set of patches ever. Eleven security updates were released although,...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.

Whitepapers

Advancing the Economics of Networking

Aging network systems and old habits have dictated how businesses spend their IT budgets. As a...

Implementing HA at the Enterprise Data Center Edge to Connect to a Large Number of Branch Offices

This paper reviews the problem of creating a network where the dynamic availability of services is...

Enterprise Data Center Network Reference Architecture

Using a High Performance Network Backbone to Meet the Requirements of the Modern Enterprise Data...

Webcasts

PoE Plus: Impact on the PoE Market

The standard for Power over Ethernet (PoE), IEEE Std. 802.3af(tm)-2003, advanced networking,...

Harnessing the power of communications to increase workplace performance

Due to the convergence of IT and telecommunications technologies, the business workplace has been...

Stay out of the headlines: Detecting and preventing network intrusions

How do YOU stay out of the headlines? There is no denying that risk exists in our computer-driven...

Special Reports

The Evolution of Network Security

We have so many holes punched in our firewalls today that many industry insiders question the value...

IP address management in 2008 - six things to know

Read this Network World Special Brief to learn how Enterprise IT managers must update their...

The self-managed network

We aren't there yet, but advances in network and systems management tools are making it possible to...