Email this article   Print article 


Microsoft Patch Tuesday's Highest Priority: IE9

By Ken Presti
November 13, 2012    4:58 PM ET

Page 2 of 2

After the IE9 patch, Lumension's Henry points to a TrueType font issue as the second most important item on the list. "There are three vulnerabilities here, the worst of which is a remote code execution," he said. "The problem is that this exploit renders at the kernel level. So if the bad guy can get that, particularly TrueType Font, and build it into an exploit, he can get root. So this is absolutely a high priority because it could be remote code executable."

"There is also a theoretical possibility that one can exploit this through third-party browsers or other third-party software," added Andrew Storms, director of security operations at nCircle.

Another patch is tied to Briefcase, a program that is no longer in wide use. "If you are using Briefcase, this should definitely be a concern," said Henry. "It's both ugly and critical, and it affects XP all the way through Windows 7. Briefcase allows you to sync files across your laptop and your desktop. But if you've mapped to a vulnerable or malicious briefcase, remote code could execute on the machine from which you have mapped."

"The briefcase vulnerability is very difficult to execute," said Miller. "It's going to be a man-in-the-middle attack. They need to get somewhere on your network in order to gain access to this. But, Briefcase is not all that common anymore."

Other patches for November include protections against remote code executions in Windows Shell and .Net, as well as a fix to a potential information disclosure breach in Microsoft Internet Information Service (IIS).

PUBLISHED NOV. 13, 2012

<< Previous | 1 | 2

To continue reading this article, please download the free CRN Tech News app for your iPad or Windows 8 device.
Related: Videos | Slide Shows | Comments

SHARE THIS ARTICLE

More Security

Recent Articles

Head-To-Head: Symantec Vs. McAfee In Endpoint Protection

McAfee and Symantec are archrivals with a firm grip on the North American security market. CRN pits both vendors' endpoint security products against each other and names a winner.

The 8 Steps Behind The Massive $45M Cyber Bank Heist

More than $45 million was stolen from banks in the U.S. and 19 other countries in a scheme that law enforcement is calling an international conspiracy to drain millions from bank accounts using stolen debit cards and PIN numbers. Here's how they did it.

Name Of The Game: Top 10 States For Identity Theft

A Federal Trade Commission report provides statistics on identity theft and fraud complaints in 2012. Learn which state has the dubious distinction of having the most victims.

  More Slide Shows




Related Videos
Loading...