Microsoft has released the following three updates that fix vulnerabilities in Windows. These updates were expected, via the company’s routine Patch Tuesday. Only one of the three updates is labeled critical. Please note that earlier this week, Microsoft received criticism that this set of updates does not fix an Excel flaw that attackers are now exploiting.
Here are Microsoft’s descriptions of today’s updates:
| Vulnerabilities in Windows Kernel Could Allow Remote Code Execution (958690)
This security update resolves several privately reported vulnerabilities in the Windows kernel. The most serious vulnerability could allow remote code execution if a user viewed a specially crafted EMF or WMF image file from an affected system. |
Critical Remote Code Execution |
Microsoft Windows |
|
| Vulnerability in SChannel Could Allow Spoofing (960225)
This security update resolves a privately reported vulnerability in the Secure Channel (SChannel) security package in Windows. The vulnerability could allow spoofing if an attacker gains access to the certificate used by the end user for authentication. Customers are only affected when the public key component of the certificate used for authentication has been obtained by the attacker through other means. |
Important Spoofing |
Microsoft Windows |
|
| Vulnerabilities in DNS and WINS Server Could Allow Spoofing (962238)
This security update resolves two privately reported vulnerabilities and two publicly disclosed vulnerabilities in Windows DNS server and Windows WINS server. These vulnerabilities could allow a remote attacker to redirect network traffic intended for systems on the Internet to the attacker’s own systems. |
Important Spoofing |
Microsoft Windows |
After reviewing today’s bulletins, security researcher, Eric Schultze, CTO of Shavlik Technologies says he agrees with Microsoft’s critical rating for MS09-006, but would also label as critical the MS09-008 patch which fixes a flaw in Windows DNS Servers. Schultze said in a written statement sent to journalists:
“MS09-008 addresses a vulnerability in DNS and WINS services that could allow an attacker to insert bad data into a DNS (or WINS) Server, thereby redirecting people’s traffic to potentially evil websites. The security bulletin doesn’t list any workarounds, nor does it imply any pre-requisites on the part of the attacker, meaning it could be possible for a remote, unauthenticated attacker to modify a vulnerable DNS Server and redirect the site’s users. … If an unauthenticated remote attacker can modify these instructions and redirect people to bogus websites then the DNS Server isn’t doing its job … that’s a pretty serious situation.”
As for the other two updates, MS09-006 fixes a vulnerability that can be exploited when viewing maliciously created graphic images. Schultze says that the flaw resides in the Windows kernel – but can only be exploited if an attacker can get the user to view a malformed pictures (Facebook anyone?). Here’s the kicker:
“The evil code will execute with system privileges – even if the user wasn’t logged on as an administrator. With system privileges, the evil code can access, copy, or delete any files on the system, create or delete user accounts, change passwords, or install backdoors. IOW, nasty stuff.”
MS09-007 is what Schultze calls “a seemingly innocuous spoofing vulnerability” that could allow an attacker to access a site without a required certificate. Most users don’t use certificate-based authentication for secure sites. An Active Directory-based certificate store, the most common when certificates are used, is not at risk from this vulnerability.
Visit the Microsoft Subnet web site for more news, blogs, podcasts. Subscribe to all Microsoft Subnet bloggers. Sign up for the bi-weekly Microsoft newsletter. (Click on News/Microsoft News Alert.)
SSH PowerShell for the massesWe-Fi: find Wi-Fi hotspots anywhere, anytime!Windows 7 post-beta leaks – why you should worryMicrosoft secretly tests uninstall option for IE in Windows 7Six of the best gadgets from Microsoft TechFestReader’s Choice for Best Windows open source Projects Microsoft to give away one million training vouchers Follow Microsoft Subnet on Twitter




