Patch Tuesday whopper: 13 patches (8 critical), plus one surprise patch for XML

Analyse
Oct 13, 20097 Minuten

Microsoft fixes a total of 32 new holes today, including two high-profile zero-day exploits

Microsoft released 13 security bulletins to address 34 vulnerabilities for its October Patch Tuesday. It also included a surprise re-release of one bulletin that adds new fixes to a year-old patch of Microsoft XML Core Services. Affected products include Windows, Internet Explorer, Silverlight, Microsoft Office, Developer Tools, Forefront and SQL Server.

Microsoft is also advising customers who like to use its Malicious Software Removal Tool (MSRT) that they should download it afresh as this month’s version will remove Win/FakeScanti.Win32/FakeScanti is a family of trojans that claim to scan for malware and display fake warnings of “malicious programs and viruses”. They then inform the user that they need to pay money to register the software in order to remove these non-existent threats. Win32/FakeScanti variants have been observed to use names such as “Windows Antivirus Pro.” Microsoft last month vowed to put an end to what it calls “maladvertisements’ scammers who use these scare tactics to get users to buy their wares. (Indeed last month is sued five of them.)

As we noted in an earlier post, this month, Microsoft is releasing patches for two high-profile vulnerabilites of which it warned users: Security Advisories 975497 and 975191, fix vulnerabilities in Microsoft Server Message Block version 2 (SMBv2) and the File Transfer Protocol (FTP) Service in Microsoft Internet Information Services (IIS), respectively.

Here is a complete summary, provided by Microsoft, and links to all the patches released today. Security researchers are analyzing the patches now and when information becomes available as to which patch to tackle first, I will update this post with links to that advice.

  • MS09-050 (Maximum severity rating of Critical) This update resolves one publicly disclosed and two privately reported vulnerabilities in Server Message Block Version 2 (SMBv2). The more severe of the vulnerabilities could allow remote code execution if an attacker sent a specially crafted SMB packet to a computer running the Server service. This update received a 1 rating from Microsoft’s Exploitability Index.

  • MS09-051  (Maximum severity rating of Critical) This security update resolves two privately reported vulnerabilities in Windows Media Runtime. The vulnerabilities could allow remote code execution if a user opened a specially crafted media file or received specially crafted streaming content from a website or any application that delivers web content. This update received a 1 rating from Microsoft’s Exploitability Index.

  • MS09-052  (Maximum severity rating of Critical) This security update resolves one privately reported vulnerability in Windows Media Player. The vulnerability could allow remote code execution if a specially crafted Advanced Systems Format (ASF) file is played using Windows Media Player 6.4. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. This update received a 1 rating from Microsoft’s Exploitability Index.

  • MS09-053  (Maximum severity rating of Important) This security update resolves two publicly disclosed vulnerabilities in the File Transfer Protocol (FTP) Service in Microsoft Internet Information Services (IIS) 5.0, IIS 5.1, IIS 6.0, and IIS 7.0. On IIS 7.0, only FTP Service 6.0 is affected. The vulnerabilities could allow remote code execution on systems running FTP Service on IIS 5.0, or denial of service on systems running FTP Service on IIS 5.0, IIS 5.1, IIS 6.0 or IIS 7.0. This update received a 1 rating from Microsoft’s Exploitability Index.

  • MS09-054  (Maximum severity rating of Critical) This security update resolves three privately reported vulnerabilities and one publicly disclosed vulnerability in Internet Explorer. The vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. This update received a 1 rating from Microsoft’s Exploitability Index.

  • MS09-055  (Maximum severity rating of Critical) This security update addresses one privately reported vulnerability in ActiveX controls that were compiled using the vulnerable version of the Microsoft Active Template Library (ATL) and could allow remote code execution if a user views a specially crafted webpage with Internet Explorer, instantiating the ActiveX control. This update received a 3 rating from Microsoft’s Exploitability Index.

  • MS09-056  (Maximum severity rating of Important) This security update resolves two publically disclosed vulnerabilities in Microsoft Windows. The vulnerabilities could allow spoofing if the attacker gains access to the certificate used by the end user for authentication. This update received a 3 rating from Microsoft’s Exploitability Index.

  • MS09-057  (Maximum severity rating of Important) This security update resolves one privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if an attacker set up a malicious webpage which invokes the Indexing Service through a call to its ActiveX component. This call could include a malicious URL and exploit the vulnerability, granting the attacker access to the client system under the privileges of the user browsing the webpage. This update received a 2 rating from Microsoft’s Exploitability Index.

  • MS09-058  (Maximum severity rating of Important) This security update resolves three privately reported vulnerabilities in the Windows kernel. The most severe of the vulnerabilities could allow elevation of privilege if an attacker logged on to the system and ran a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. This update received a 2 rating from Microsoft’s Exploitability Index.

  • MS09-059  (Maximum severity rating of Important) This security update resolves one privately reported vulnerability in Microsoft Windows. The vulnerability could allow denial of service if an attacker sent a maliciously crafted packet during the NTLM authentication process. This update received a 3 rating from Microsoft’s Exploitability Index.

  • MS09-060  (Maximum severity rating of Critical) This security update resolves three privately reported vulnerabilities in Microsoft Active Template Library (ATL) ActiveX Controls for Microsoft Office. The vulnerabilities could allow remote code execution if a user loaded a specially crafted component or control hosted on a malicious website. This update received a 3 rating from Microsoft’s Exploitability Index.

  • MS09-061  (Maximum severity rating of Critical) This security update resolves three privately reported vulnerabilities in Microsoft .NET Framework and Microsoft Silverlight. The vulnerabilities could allow remote code execution on a client system if a user views a specially crafted webpage using a web browser that can run XAML Browser Applications (XBAPs) or Silverlight Applications, or if an attacker succeeds in persuading a user to run a specially crafted .NET application. This update received a 1 rating from Microsoft’s Exploitability Index.

  • MS09-062  (Maximum severity rating of Critical) This security update resolves eight privately reported vulnerabilities in Microsoft Windows Graphics Device Interface (GDI)+. These vulnerabilities could allow remote code execution if a user viewed a specially crafted image file using affected software or browsed a website that contains specially crafted content. This update received a 1 rating from Microsoft’s Exploitability Index.

  • Microsoft re-released Security Bulletin MS08-069 to add detection for MSXML on Windows 7 and Windows Server 2008 R2.

Like this post? Check out these others.
  • Microsoft, researchers release new operating system project: Barrelfish
  • Virtual Computer solves the XP to W7 upgrade problem
  • The iland Workforce Cloud: Go ahead keep your head and desktop in the cloud
  • Avaya Buys Nortel. What’s that mean for Microsoft?
  • Use FILESTREAM Data in 2008 but watch out…
  • Keys to Creating Successful Global Teams
  • Why you need vendors to adopt OVF before you move to the cloud
  • Virtualization Day: Virtual Machine Manager R2 RTM and Windows 7 XP Mode
Plus, visit the Microsoft Subnet web site for more news, blogs, podcasts. Subscribe to all Microsoft Subnet bloggers. Sign up for the bi-weekly Microsoft newsletter. (Click on News/Microsoft News Alert.) All Microsoft Subnet bloggers on Twitter Julie Bort on Twitter

Follow

Follow