Emergency fix released for Windows threat
Microsoft issued a high-priority fix to a critical Windows vulnerability today that should be applied to both clients and servers, but said that if you’re short on time, apply the patch to the clients first.
The issuance of this out-of-band — meaning it couldn’t wait until the next Patch Tuesday Aug. 10 — security update is intended to patch a vulnerability in all versions of Windows that my colleague Julie Bort described as “a whopper on all levels.” Called a “rootkit,”it can enter the system through a USB drive or through shared files and reveals itself on a desktop as a shortcut icon. One doesn’t even have to click on the icon to execute the exploit, which installs malware on the computer.
In a Web cast this morning to explain the fix and answer questions, Christopher Budd, senior security response communications manager at Microsoft, acknowledged that because of the way the infection presents itself via a desktop icon, it’s more important to install the patch on clients than servers. But he warned IT staff not to dawdle on updating the servers, too, to fully protect their systems.
“The exploits do require some user interaction,” Budd said. “You can certainly factor that in terms of your prioritization of the security update, but we would not recommend that you use that to justify not applying the security update [to servers].”
In the hour long Web cast, Budd addressed reports that a short-term workaround to protect against the exploit, while a permanent patch was designed and tested, had some negative side effects. The workaround blocked legitimate shortcut icons from loading, an unfortunate consequence he described as a “big hammer type approach.” Rest assured, he added, once the security update is deployed, the workaround will be automatically removed and functionality of icons will be restored.
The vulnerability applies to all versions of Windows, even to fully-patched versions of Windows 7, but the patch doesn’t apply to all. It is not going to fix machines running Windows 2000 or Windows XPSP2 (Service Pack Two). Organizations running those operating systems will need a custom support agreement with Microsoft to get a patch or upgrade to at least Windows XPSP3 or they’re out of luck.
The vulnerability, first acknowledged by Microsoft July 16, was discovered in the Windows Shell component of the OS and the malware that exploits it seems intended for espionage, according to various security experts.
Asked on the Web cast whether security software running on a system will protect against the infection, Budd said maybe, but security software isn’t 100 percent effective; only applying the update is 100 percent effective.
For Microsoft to issue this patch today, instead of lumping it in with all the scheduled Patch Tuesday updates next week, is an indicator of the seriousness of the threat. Budd blogged last week that while Microsoft had no knowledge of malware attacks, “we’ve seen an increase in attempts to exploit the vulnerability.”
Despite the urgency, some IT staffers have limited time and budgets to immediately install patches, like a fire department with three alarms sounding but only one truck. Budd said Microsoft has released as much detail as it can about the vulnerability so each IT administrator can determine the risk relative to their particular system.
“At the end of the day, the decision to roll this out today versus rolling it out with next week’s regularly scheduled update is one you’re going to have to answer for yourself,” he said.




