Microsoft issues eight Windows fixes

Topics

Windows, Patch, Flaw

NEWS

Microsoft on Tuesday provided fixes for eight flaws related to Windows, including three that could be used to compromise a system without any user interaction.

As expected, the company issued six security bulletins as part of its monthly patch cycle. Five of the updates were tagged "critical", Microsoft's highest rating of attack risk. One alert, MS06-069, calls out flaws in Adobe Systems' Macromedia Flash Player, which shipped with Windows XP. The others cover vulnerabilities in Microsoft software.

All of Microsoft's fixes address vulnerabilities in software related to its Windows operating system. Three of the security holes could be exploited remotely by an anonymous attacker without the user having to take any action, such as clicking on a link. The remaining five would require people to visit a malicious website or open a malicious file for an attack to succeed, according to Microsoft's alerts.

The most urgent issue is a flaw in Microsoft's "Workstation Service" in Windows 2000 and Windows XP, said Amol Sarwate, a research manager at vulnerability-management company Qualys. "Attackers can remotely send malicious packets and cause code execution," he said. The problem is described in Microsoft alert MS06-070.

The Workstation Service routes file system and print requests, both local and on a network. It is a key part of Windows that can't be turned off or easily protected by a firewall, Sarwate said. "Really, the only solution is to apply the patch as soon as possible," he said.

The problem is most severe for Windows 2000, said Christopher Budd, a security program manager at Microsoft. "There is the potential risk of a worm for Windows 2000, but you don't have that with Windows XP SP2," he said. The threat to Windows XP is mitigated because of its firewall and different networking technology, Budd said.

A hacker could exploit the Workstation Service flaw by creating a specially crafted message and sending it to a vulnerable computer. "An attacker who successfully exploited this vulnerability could take complete control of the affected system," Microsoft said in its security bulletin, which it rates "critical".

More worm holes
Two other vulnerabilities expose Windows machines to a similar risk of being used to spawn worms. These affect Microsoft's Client Service for NetWare and the NetWare Driver, which let Windows systems access network services on servers running Novell NetWare. However, this software is not installed by default.

"The NetWare software could be turned off. It is just less prevalent," Sarwate said. In security bulletin MS06-066, Microsoft deems the NetWare issues "important", one notch below "critical" in its four-tiered rating scheme.

The WorkStation Service and NetWare flaws are the network security issues addressed by Microsoft's bulletins. The other problems require some form of user action to be exploited and are known as client-side flaws.

The Microsoft Agent, a help tool that succeeded the famous Clippy Office assistant, is flawed in the way it handles certain files, Microsoft said in bulletin MS06-068. Opening a malformed ".acf" file could cause PC compromise, it said.

Patching zero-days
The WorkStation Service, NetWare and Agent issues had not been disclosed earlier, which means there are no known attacks that exploit these flaws. Some of Microsoft's other fixes, however, are for vulnerabilities that are already being used in attacks.

A "critical" update for Internet Explorer, MS06-067, addresses three vulnerabilities, two of which cybercrooks are already tapping. An expected patch for XML Core Services delivered with bulletin MS06-071 plugs a flaw in that Windows add-on that had also surfaced in cyberattacks.

The IE update also addresses a new flaw, which lies in the way it handles certain HTML, or hypertext markup language, layout combinations, Microsoft said.

"Many of the issues addressed in this month's batch of patches attend to publicly exploited issues," Alfred Huger, a senior director at Symantec Security Response, said in a statement. "Attackers are exploiting vulnerabilities with increasing speed, and it's imperative that computer users protect themselves by installing updated software patches as quickly as possible."

Post your comment

In order to post a comment you need to be registered and logged in

Log in or create your ZDNet UK account below

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Membership FAQ

ZDNet UK Live

apexwm

Fedora is the same way as well. The yum update system uses "presto" which shrinks the amount of data needed for download. It's a great system....

11 hours ago by apexwm on Can you believe it - 2765 kB will be freed?
cybfor

Updated ID cards considered for 2012: [zdnet.co.uk] The government is considering introducing a new generation of ID... http://dlvr.it/KpBZ

cybfor

Google, Viacom trade blows in YouTube copyright spat: [zdnet.co.uk] Google and the US media giant Viacom have issued... http://dlvr.it/Knht

CIMITL

Be sure to include an audio option - eg. a beep tone - to intensify and reiterate the action. This will greatly benefit some consumers and give...

13 hours ago by CIMITL
DataSecurityUK

Data disposal is really important to get right. There are standards set by UK and US federal governments to ensure that data is kept secure. If...

13 hours ago by DataSecurityUK
chaycon1

Online Fiber Optic Certification Join a talented group of professionals, who are dedicated to Fiber Optic Networking technology. The online course...

15 hours ago by chaycon1 on BT launches 40Mbps fibre-based broadband
chaycon1

Online Fiber Optic Certification Join a talented group of professionals, who are dedicated to Fiber Optic Networking technology. The online course...

15 hours ago by chaycon1 on Google to build gigabit broadband to the home
J.A. Watson

Hi Dava, I'm glad to hear from you, and glad that you see things from the other side. I think that is the most important point of the whole...

16 hours ago by J.A. Watson on Ubuntu 10.04 (Lucid Lynx) and the Latest Tempest
dava4444

please please please please please please kill that spam bot.

16 hours ago by dava4444 on ZDNet UK: faster, smarter, still IT all the way
253chelisa253

hi

16 hours ago by 253chelisa253 on How security will look in 10 years
lezlow

it is only greedy[microsoft]?

18 hours ago by lezlow on Researchers break into BitLocker
dava4444

it didn't post the link it's 'Ubuntu 10.04 Lucid Lynx Beta-1 First Look' on youtube :) Dava

19 hours ago by dava4444 on Ubuntu 10.04 (Lucid Lynx) and the Latest Tempest
dava4444

Hi James I disagree, Ubuntu needs a GUI update and this one IMO is quite good. your pics show a low res. here's a high res. on YouTube* The...

19 hours ago by dava4444 on Ubuntu 10.04 (Lucid Lynx) and the Latest Tempest
dava4444

Hi any news on the comment bot? knocking me back from my own blog is a bit cheeky lol *Mulder to Scully* "I think it has an agenda.." I know, I...

20 hours ago by dava4444 on ZDNet UK: faster, smarter, still IT all the way
benny boy

if you look at the Brentwood exchange on samknows it servers 21,000 residential propertiesm, Lowestoft serves 31,000! Come on BT sort yourselves...

20 hours ago by benny boy on BT fibre broadband coming to 69 more towns
pbreddit

[programming] H.264 - a sting in the tail http://reddit.com/bfu4q [zdnet.co.uk]

reddit

H.264 - a sting in the tail [programming] 13 points, submitted by zigzag [zdnet.co.uk] http://reddit.com/bfu4q

cybfor

Malware infects second Vodafone HTC phone: [zdnet.co.uk] A second Android-based HTC Magic from Vodafone has been... http://dlvr.it/KhKx

miyabi81

Chatter preview http://www.zdnet.co.uk/news/application-development/2010/03/17/salesforce-opens-up-chatter-developer-preview-40088348/

cybfor

US gov t considers undercover social networking: [zdnet.co.uk] The Obama administration has considered sending... http://dlvr.it/Kh3L

Featured white papers

Achieving PCI Compliance for:Privileged Password Management & Remote Vendor Access

For multi-store outlets, including retail, banking, grocery, gas, hospitality, convenience stores and others, reducing (or avoiding) the cost of in-store system support and maintenance while maintaining compliance with PCI and other requirements has become a strategic challenge.

Download now

Web 2.0 Security Threats: How to Protect Your Enterprise Network

Speaker: Dr. Chenxi Wang, Principal Analyst, Security and Risk Management, Forrester Research, Inc. As Enterprises are increasingly connected to the Internet and as hard organizational boundaries are fast disappearing, security professionals are facing fresh challenges in Enterprise computing.

Download now

MindManager - Tutorial for New Users - Short

This tutorial is for new MindManager users and teaches you how to get started, by creating maps, reading maps and organizing your information.

Download now