Security threats Toolkit
Story: Microsoft prepares to patch critical Windows hole
and time for you to prepare for 2009......
Interesting to see that Microsoft did not release an out of band patch for Microsoft Security Advisory (961040), which addresses a vulnerability in SQL Server. The company has published a workaround, however, it seems they will NOT correct the fundamental, architectural vulnerability. Lookout on to see if they also inlcude it in the update next week.
The light load really presents a good opportunity for IT administrators to get their “housecleaning” in order to kick off the 2009 security planning process. This means getting their vulnerability and patching program in place by ensuring all previous patches, both Microsoft and non-Microsoft, have been deployed across their environment using best practices and re-evaluating ways to maximise on their patching process moving forward. For example, for administrators who failed to patch MS08-67 for the RPC vulnerability that was reported back in October 2008, this is the best time to go back and patch the issue as security experts are starting to see new variants appearing in the wild. There is widespread use of the vulnerability today than back in October.
Full Talkback thread









