Sponsored Links/Advertisements

Microsoft Patch Tuesday Brings Four Fixes For Eight Flaws

As part of its February patch cycle, Microsoft (NSDQ: MSFT) on Tuesday released four security bulletins addressing eight vulnerabilities in its software.

Two of the bulletins are designated “critical” and two are designated “important.” They aim to fix vulnerabilities in Internet Explorer, Microsoft Exchange, SQL Server, and Visio.

* MS09-002 (maximum severity of critical): This update resolves two newly discovered and privately reported vulnerabilities in Internet Explorer that could allow remote code execution if a user views a specially crafted Web page using Internet Explorer.

* MS09-003 (maximum severity of critical): This update resolves two newly discovered and privately reported vulnerabilities in Microsoft Exchange. The first vulnerability could allow remote code execution and the second could allow denial of service.

* MS09-004 (maximum severity of important): This update resolves a newly discovered and privately reported vulnerability in SQL Server, which could allow remote code execution if untrusted users access an affected system or if a SQL injection attack occurs to an affected system.

* MS09-005 (maximum severity of important): This update resolves three newly discovered and privately reported vulnerabilities in Microsoft Office Visio that could allow remote code execution if a user opens a specially crafted Visio file.

Microsoft also released Security Advisory 960715, which updates a set of previously published ActiveX kill bits. The new kill bits follow from Microsoft security bulletin MS08-070 and affect Akamai Download Manager and Research in Motion AxLoader.

Eric Schultze, CTO of Shavlik Technologies, considers MS09-004 to be the most interesting patch this month. “This patch addresses the zero-day SQL Server flaw reported by Sec-Consult” on Dec. 9, he said in a statement. “This flaw enables attackers to execute code of their choice on the affected SQL Server. The bar for exploitation is raised slightly in that the attacker must already have authenticated access to the SQL Server in order to pull off this exploit.”

Because proof-of-concept exploit code for this vulnerability has been published already, Schultze suggests MS09-004 ought to be rated “critical.” He advises patching MS09-003 and MS09-004 as soon as possible; MS09-002 and MS09-005, he says, can wait until a more convenient time.

Paul Zimski, VP of market strategy for Lumension, argues that MS09-002, the Internet Explorer patch, also needs to be dealt with right away. “The remote code execution vulnerabilities exist in IE7 on both Windows XP and Windows Vista — probably the most prevalent Windows configurations in use today,” he said in a statement. Microsoft, he added, gives this vulnerability a score of one on its Exploitability Index, meaning that exploit code can be created easily.

A recent report argues that Microsoft should make its operating system open source, pay more attention to cloud computing, and get out of search. Download “Overhauling Microsoft” to find out why (registration required).

Source: informationweek.com

V

Me from India ;)

One response to “Microsoft Patch Tuesday Brings Four Fixes For Eight Flaws”

  1. Dave Thompson

    One problem I have noticed with 961260 is that one of our Access based applications (Access frontend, SQL backend) that uses the (MS)HierarchicalFlexGrid control failed to work with the message in VBA:
    Runtime error ‘438′:
    Object doesn’t support this property or method

    when trying to perform any action on the control.

    The only solution I have found so far is to remove the update.

Leave a Reply

Subscribe and Get Hottest News and Pics!

Subscribe to indihot

Powered by us.groups.yahoo.com

Recent Comments

  • Asim Khan: Hi This is Asim Khan
  • suresh: plz send me the release date of results of SSC narcotics intelligence bureau.
  • DEBASIS MALICK: Dear Sir, I am, (DEBASIS MALICK), I have appear in 2009 Assistant Engineer (Mechanical) : 06 posts...
  • me marathi manus: ae sana tumhi bihari lokach india che developement thambavatat aahe. mumbai madhye yaun aamchya...
  • me marathi manus: ae sudeep jasa tula hindi var prem aahe na.tasech aamhala marathi var prem aahe. tujhya rahul...
  • me marathi manus: marathi mansache manatle faqta raj sahebach odakhu shaktat . me marathi. jai maharashtra.
  • Jhuma mondal: appeared on 20th dec 2009 for the post of assistant engineer . pls let me know whether i have been...
  • sandip: i would like to know written test date
  • sai: mama these all are rumours in fact they are good friend’s dont spoil u r time in dis any way thier is no...
  • mahmood khan: please give me the rate of gold todays price