Six Microsoft patches fix 12 vulnerabilities in IE8, XP, Vista, Windows Server and Office. Microsoft also released two optional patches.
Today is Patch Tuesday and, as expected, Microsoft is releasing six updates, three rated critical, that fix 12 holes in Windows, Internet Explorer, Windows Server and Microsoft Office. Additionally, Microsoft is re-releasing a patch that offers additional fixes for a Domain Name Service hole in Windows 2000 Service Pack 4. It has also issued two security advisories to offer workarounds and optional patches for two other vulnerabilities.
The place to start is MS09-072, says Jerry Bryant, senior security program manager lead for Microsoft. This is a critical patch that fixes four privately reported vulnerabilities and one publicly disclosed vulnerability in Internet Explorer which could allow remote code execution. It has the most severe rating on Microsoft’s Exploitability Index, meaning that Microsoft has either confirmed the existence of exploit code in the wild, or thinks it’s likely that attacks will materialize soon. In this case, Bryant says that Proof of Concept (PoC) code for this IE8 hole is already out there.
Note that MS09-070 also carries a rating of 1 on the Exploitability Index. It fixes vulnerabilities in Active Directory Federation Services that could allow remote code execution, and affects Windows Server 2003, Windows Server 2003 x64 Edition, Windows Server 2008, and Windows Server 2008 x64 Edition, but it only carries a severity rating of “important” because an “attacker must have valid logon credentials to the vulnerable server. An attack can only be carried out after authenticating successfully to the server that supports ADFS,” says Microsoft.
But the surprise of this month’s Patch Tuesday is that Microsoft is releasing two security advisories that offer optional patches or workarounds regarding the Integrated Windows Authentication (IWA) hole and the Indeo codec vulnerability.
The IWA hole is a man-in-the middle attack. Microsoft says this attack can be avoided by downloading the optional Extended Protection for Authentication feature available for Windows. Microsoft says, “This feature enhances the protection and handling of credentials when authenticating network connections using Integrated Windows Authentication.” The TechNet article doesn’t offer any explanations as to why this would be an optional patch or feature.
The Indeo codec tends to be in use in older Windows versions, Microsoft Windows 2000, Windows XP, and Windows 2003. Microsoft isn’t offering a patch and as far as anyone knows, isn’t planning on offering it. Instead it wants folks to download an optional add-on feature that blocks the Indeo codec from being launched in Internet Explorer or Windows Media player. The optional update also removes the ability for this codec to be loaded when browsing the Internet with any other applications. Because this patch could interfer with legacy business applications, Microsoft is releasing this patch as an advisory, making it option, although it will be pushed out to customers who are using one of Microsoft’s automatic update mechanisms.
While we’re talking patches, Adobe also released a patch today, points out Jason Miller, Data and Security Team Leader, for patch vendor Shavlik Technologies. In an e-mail sent to me, he writes, “Adobe is also joining this patch Tuesday with the release of a new Adobe Flash Player and Adobe Air. This security patch will address critical software vulnerabilities. There is no word from Adobe yet on how many vulnerabilities are addressed and if they are publically known or exploited at this time. Any Adobe Flash Player less than version 10.0.32.18 and any Adobe Air less than version is affected by this vulnerability(ies). ”
The Microsoft Security Research Center (MSRC) and Security Research & Defense (SRD) blogs also contain an embedded video with Jerry Bryant and the Microsoft Security Response Center’s (MSRC) Adrian Stone explaining the vulnerabilities and fixes.
Additionally, Bryant and Stone will host a webcast on Dec. 9, at 11:00 a.m. PST (UTC -8) to provide more detailed information regarding the bulletins and answer customer questions.
Here is the full list of links and brief descriptions of today’s Patches, provided by Microsoft.
- MS09-069 (Maximum severity rating of Important): This update resolves one privately reported vulnerability in Windows which could allow denial of service. This update received a 3 rating from Microsoft’s Exploitability Index.
- MS09-070 (Maximum severity rating of Important): This update resolves two privately reported vulnerabilities in Windows which could allow remote code execution; however, an attacker would need to be an authenticated user in order to exploit either of these vulnerabilities. This update received a 1 rating from Microsoft’s Exploitability Index.
- MS09-071 (Maximum severity rating of Critical): This update resolves two privately reported vulnerabilities in Windows which could allow remote code execution. This update received a 2 rating from Microsoft’s Exploitability Index.
- MS09-072 (Maximum severity rating of Critical): This update resolves four privately reported vulnerabilities and one publicly disclosed vulnerability in Internet Explorer which could allow remote code execution. This update received a 1 rating from Microsoft’s Exploitability Index.
- MS09-073 (Maximum severity rating of Critical): This update resolves one privately reported vulnerability in Office which could allow remote code execution if a user opens a specially crafted Project file. This update received a 2 rating from Microsoft’s Exploitability Index.
- MS09-074 (Maximum severity rating of Important): This update resolves one privately reported vulnerability in Office which could allow remote code execution. This update received a 2 rating from Microsoft’s Exploitability Index.
- Microsoft re-released MS08-037 to reoffer the update for the DNS Client for Windows 2000 Service Pack 4.
- Microsoft released Security Advisory 954157 to provide security mitigations to the Indeo codec on supported editions of Microsoft Windows 2000, Windows XP, and Windows Server 2003.
- Microsoft released Security Advisory 974926 to address the potential for attacks that affect the handling of credentials using Integrated Windows Authentication (IWA) and the mechanisms Microsoft has made available for customers to help protect against these attacks.
- Microsoft revised Security Advisory 973811 to provide Extended Protection for Authentication, on the Windows platform. This feature enhances the protection and handling of credentials when authenticating network connections using Integrated Windows Authentication (IWA).
Like this post? Check out these others.
Plus, visit the Microsoft Subnet web site for more news, blogs, podcasts. Subscribe to all Microsoft Subnet bloggers. Sign up for the bi-weekly Microsoft newsletter. (Click on News/Microsoft News Alert.)
- Prevx apologizes, backtracks on claims that Microsoft patch causes black screen
- Secrets of Exchange Server 2010
- Unified Messaging (Voicemail) in Exchange 2010
- Microsoft’s Teamprise acquisition means nothing for open development
- Microsoft’s data cache technology, code-named Velocity, speeds app performance
- SQL Server 2008 R2: November CTP Feature Pack
- F5 announces new management pack for OpsMgr 2007
- Microsoft Linux: Why one free software advocate wants it
- Server Sizing in Exchange 2010
Follow All Microsoft Subnet bloggers on Twitter
Follow Julie Bort on Twitter




