Email this article   Print article 


Microsoft Issues A Long List Of Fixes For Patch Tuesday

By Ken Presti
August 14, 2012    6:27 PM ET

Page 1 of 2

Microsoft has released a string of security fixes in conjunction with its August Patch Tuesday.

As previously indicated, Microsoft's dispatch includes nine bulletins, five of which are rated critical and are in need of immediate attention. Additionally, Oracle and Adobe have each announced patches of their own that largely correspond to effectively closing the Microsoft vulnerabilities.

One of the most critical Microsoft bulletins involves a vulnerability in Windows Common Controls. "This one takes the cake," said Andrew Storms, director of security operations at nCircle. "It's similar to a bug they patched in April, but this time the attack vector is an RTF file. The effect is somewhat reduced because you have to open the file; it's not a preview pane kind of thing. But, they are now saying that they have seen limited targeted attacks out in the wild."

[Related: Oracle To Issue Patch To Close Vulnerability In Database Server, Other Products]

But, Paul Henry, security and forensic analyst at Lumension Security, believes that the highest criticality for August goes to the XP patch for RDP. "This is a remote code vulnerability, and no authentication is required," he said. "We've had a string of RDP patches, and people might think they've already patched it. But, this is a different one, and it should be a top priority to get that patch rolled out."

Windows Remote Desktop (RDP) is in use by a substantial number of administrators as a tool in system management. "The key word for this exposure is 'unauthenticated,'" said Jason Miller, manager of research and development at VMware. "If the attacker sends malicious unauthenticated packets, that attacker could gain control. And, that usually translates to a worm of some sort. Even if you don't have an RDP enabled by default, it could be turned on at any time. So, any time you have anything that can be attacked by an unauthenticated user, you have to act right away."

NEXT: A Dual IE8 Fix

1 | 2 | Next >>

To continue reading this article, please download the free CRN Tech News app for your iPad or Windows 8 device.
Related: Videos | Slide Shows | Comments

SHARE THIS ARTICLE

More Security

Recent Articles

10 Security Companies That Have Scored CIA Funding

CIA-funded venture firm invests millions in technology startups, mostly security firms. Find out which security companies won In-Q-Tel funding.

Head-To-Head: Symantec Vs. McAfee In Endpoint Protection

McAfee and Symantec are archrivals with a firm grip on the North American security market. CRN pits both vendors' endpoint security products against each other and names a winner.

The 8 Steps Behind The Massive $45M Cyber Bank Heist

More than $45 million was stolen from banks in the U.S. and 19 other countries in a scheme that law enforcement is calling an international conspiracy to drain millions from bank accounts using stolen debit cards and PIN numbers. Here's how they did it.

  More Slide Shows




Related Videos
Loading...