Microsoft released two security updates for its Windows operating system Tuesday to patch flaws that could give attackers new ways to install malicious software on a victim's computer.
The MS08-069 update fixes critical flaws in the Microsoft XML Core Services used by Internet Explorer and other programs to render Web pages. The second MS08-068 update fixes a less-critical bug in the Windows SMB (Server Message Block) software used by Windows to share files and print documents over a network.
[ Discover the top-rated IT products as rated by the InfoWorld Test Center. ]
Hackers routinely use Web bugs such as these XML flaws to infect Windows machines. "Anytime Microsoft updates Web vulnerabilities they're going to rate them as critical," said Andrew Storms, director of security operations with security vendor nCircle. For a Web-based attack to work, the victim must first visit a compromised Web page or open an e-mail that displays the malicious code.
Microsoft rates the SMB update as "important" for Windows XP, 2000 and Server 2003 users, and only "moderate" on Vista and Server 2008. But enterprise users should still take it very seriously, said Eric Schultze, chief technology officer at Shavlik Technologies.
While a firewall would block an SMB attack from the Internet, someone who controlled a machine within the corporate network could exploit this flaw to get access to another computer in what's known as an SMB relay attack. "I would label this as critical on a corporate network," he said.
To make matters worse, the SMB flaw was already publicly disclosed prior to Tuesday's updates, Microsoft said.
With just two updates, this is one of the quieter patch releases Microsoft has had this year. But there was some excitement at the end of October when Microsoft took the unusual step of issuing an emergency patch for a bug in the Windows Server service.
Microsoft had spotted this flaw being used in a small number of targeted attacks, and the bug was considered so serious that Microsoft decided to rush out the early patch ahead of Tuesday's regularly scheduled security updates. This flaw has not been used in widespread attacks, however, security vendors say.
This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.
Download now »Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.
Download now »
The emergence of WLANs has created a new breed of security threats to enterprise networks.
Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation
Effectively address data protection challenges, implementing solutions that help store and protect businesscritical data while cutting costs and improving efficiency and reliability.
Download now »
Sign up to receive Security Resource Alerts
This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.
Download now! »Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.
Download now! »Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.
Download now! »