Advertisement
Promo

Security threats Toolkit

Story: Microsoft to fix zero-day SMB, IIS holes

  • Previous comment

Posted by: lumension (Tuesday 13 October 2009, 5:17 PM)

  • Reply

BUSY PATCH TUESDAY!!

Bulletin 5 presents an increased threat for drive-by malware because it concerns the most current versions of IE - versions 7 and 8 - on multiple operating system platforms making this vulnerability a prime target for web-born malware writers and malicious web operators.

Of the batch, Bulletin 12, raises a red flag. Labelled as critical, it affects a large number of operating systems, core services and applications. Given its prevalence, it is most likely a low level vulnerability shared within the operating system itself that needs to be fixed. If exploited, it could allow the propagation of an Internet worm without user action. Before deploying this patch into production environments, it is essential that IT administrators test it vigorously to ensure services are not impacted by unexpected results.

Organisations should also pay close attention to the details listed in Bulletins 7 and 9, two important vulnerabilities, to determine how critical they are within their business environments. Vulnerabilities involving spoofing and elevation of privilege should raise an alarm for IT administrators as they can potentially have a big impact on their ability to verify trusted destinations and control user privileges within their organisations – two conceptual things that IT never wants to lose control over.

In addition to these four bulletins, all of the critical vulnerabilities are labelled as remote code execution, which require a restart and are across a broad variety of Windows platforms and applications.

Private message disabled

lumension

lumension
LONDON, UK
Member since: October 2008

Site Activity Rating:

3

 


  • Previous comment

  • Reply to this comment
  • Return to story
  • Report this as offensive


Full Talkback thread

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

Post a comment

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters