Advertisement
Promo

Security threats Toolkit

Story: Microsoft rolls out record Patch Tuesday fixes

  • Previous comment

Posted by: lumension (Wednesday 10 June 2009, 8:56 AM)

  • Reply

Patch Management - Prioritise and Implement to address Critical Risks

In amongst the long list of patches for this patch Tuesday, there are six critical patches that IT departments should definitely address for their organisations. Some require prioritisation, and swift action.

MS09-019 is the most important in that it addresses seven separate vulnerabilities across Internet Explorer 6 and 7 for both XP and Vista. This means that almost all Windows users will soon be vulnerable while browsing the web. Two of the vulnerabilities that this update addresses are rated “1” on Microsoft’s “Exploitability Scale” meaning that exploits are likely. These vulnerabilities are in the DHTML and HTML object handling capabilities of Internet Explorer, the core technologies in almost every web page. Additionally, this patch requires a reboot so there is an additional level of complexity in ensuring that this patch is fully deployed across the enterprise.

As MS09-018 addresses an Active Directory vulnerability that is rated a 1 on the exploitability scale and addresses a key infrastructure service, it should also be prioritised. It addresses a “critical” remote code execution for Windows Server 2000 and “important” denial of service vulnerabilities on more recent Microsoft server platforms, something to be avoided on an organization’s directory services infrastructure!

Private message disabled

lumension

lumension
LONDON, UK
Member since: October 2008

Site Activity Rating:

3

This member is ranked #84 in our top 100


  • Previous comment

  • Reply to this comment
  • Return to story
  • Report this as offensive


Full Talkback thread

Sentry Posts Blog

Security Videos by Industry Leaders

The Academy Pro presents vendor and open source security products in video format. The 500+ free videos cover everything from firewalls, penetration testing, IDS/IPS to NAC and anti-spam.... More

Post a comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters