Email this article   Print article 

Microsoft To Fix SMB, FTP Flaws In 13-Patch Update

By Stefanie Hoffman, CRN
October 08, 2009    8:36 PM ET

Microsoft is set to repair 34 vulnerabilities in 13 security updates for its upcoming Patch Tuesday release, including fixes to zero-day vulnerabilities in the Microsoft Server Message Block and FTP Service.

Microsoft deemed eight of the 13 security patches critical. These patches plug holes in Windows and Internet Explorer that could enable remote hackers to launch malicious code intended to infiltrate users PCs and steal information. The patches also address glitches in Office, SQL Server, Microsoft Forefront, Silverlight and Microsoft Developer Tools.

Two of the patches included in the October update repair vulnerabilities already made public with published exploit code.

One of the patches repairs a critical vulnerability in the Microsoft SMB version 2 implementation, affecting Widows 7 and Vista, as well as XP, 2000, Server 2003 and Server 2008, which occurs in the way that the network file sharing protocol parses SMB requests. If exploited, the vulnerability opens the door for remote hackers to infiltrate Windows Vista and Server 2008 systems to steal data.

Microsoft offered users a workaround to the vulnerability last month by telling them to cut support for the SMB version 2 protocol, providing a link to the Microsoft "Fix it" package which disabled the protocol and then stopped and started the Server service.

In addition, the upcoming Patch Tuesday security update shores up a zero-day vulnerability in the FTP Service in numerous versions of the Microsoft Internet Information Services, which could allow attackers to execute malicious code or launch denial of service attacks on systems running the FTP Service.

Microsoft issued a security advisory last month warning users of "limited attacks" exploiting the FTP vulnerability, after detailed exploit code was published on the Web last month. Specifically, the vulnerability could allow attackers to launch malicious code to infiltrate a company's FTP server running on Microsoft Internet Information Services 5.0 or launch denial of service attacks on systems running the FTP Service on IIS 5.0, IIS 5.1, IS 6.0 or IIS 7.0.

Security experts contend that the FTP vulnerability was mitigated in part by the fact that the majority of FTP servers are open source versions, and not Microsoft's FTP Service.

In addition to eight critical patches, Microsoft is also releasing five patches with the slightly less severe ranking of "important," which could allow hackers to launch spoofing and denial of service attacks, as well as remote code execution.

Users will be able to download the patches directly at the Microsoft Download Center on the company's Web site.


Email this article   Print article 

More Security

Recent Articles

Symantec's Code Red: The Law Enforcement/Anonymous E-Mail Exchange

Law enforcement officials negotiated via e-mail for more than two weeks with an Anonymous group member trying to extort $50,000 from Symantec to keep stolen product code off the Internet.

How To Sell IT Security Services To Your Customers

Cyberattacks can cost a business thousands, even millions, of dollars, and can deal a death blow to some. Here's how IT solution providers can help guard against malicious attacks.

Cybersecurity Experts: What They Know Could Scare You

A recent report based on interviews with security experts in government, business and academia finds more than half in agreement that a worldwide arms race is taking place in cyberspace.

  More Slide Shows




Related Videos
Loading...