Follow Us

Nine new patches from Microsoft

But company leaves one hole open.

Microsoft has delivered six security updates to patch nine vulnerabilities. Although the patches fix two bugs now being used by hackers but leave one still open to exploit.

Of the six bulletins, three patched some part of Windows, while the remainder plugged holes in Publisher, Internet Security and Acceleration Server (ISA), and Microsoft's virtualisation software. Six of the nine bugs were ranked critical, Microsoft's highest ranking in its four-step score, while three were tagged as "important," the next-lowest label.

"We got what we expected," said Andrew Storms, director of security operations at nCircle Network Security. "We got the 'kill bit' we were looking for in the ActiveX control, and the DirectShow fix," he said, referring to two recent vulnerabilities that attackers have been exploiting for weeks.

In May, Microsoft acknowledged ongoing attacks exploiting a bug in DirectShow, one of the components in Windows' DirectX graphics platform. Last week, it owned up to a bug in a video streaming ActiveX control used by Internet Explorer (IE), which it had known about - but not fixed - for the past 18 months. Last Thursday, Microsoft had gone into unusual detail to describe the upcoming patches, and promised that both the DirectShow and ActiveX bugs would be patched.

Microsoft also delivered patches today for two critical vulnerabilities in a Windows' font engine, and one important bug each in Publisher 2007, ISA 2006, and the client and server editions of its virtualization software.

"MS09-029 and MS09-030 are bucking the trend," said Storms, talking about two of the six bulletins released today. "Typically, Microsoft's newer software is more secure, but that's not the case here."

The fix for the Embedded OpenType (EOT) Engine in MS09-029 is rated critical in all versions of Windows, including Vista and Server 2008, which if not immune from many attacks, are often less threatened by exploits because of additional security measures baked into those operating systems. And the Publisher patch in MS09-030 fixes a file format flaw in the newest 2007 edition.

"The fact that we got them both in the same month is probably just a coincidence," said Storms, "but it doesn't surprise me that researchers are looking at the newer software, because it's the newer software that's being deployed."

Missing from today's batch was a patch or automated "kill bit" solution for another ActiveX control vulnerability that Microsoft disclosed only yesterday. web attacks exploiting that bug are rapidly increasing, but Microsoft said that it wouldn't be able to wrap up a fix in time for today.






Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

State of software security report volume 4

If your business has anything worth protecting, be it money, intellectual property or a trusted...

Download Whitepaper

New threats demand innovative responses

Financial institutions in the UK remain susceptible to further systemic problems, as challenging...

Download Whitepaper

Delivering a competitive advantage through IT

IT organisations share a common mission; to optimise investments and streamline operations to...

Download Whitepaper

6 tips to mobilise your existing ERP

Enterprise mobile users throughout the global business community will number 1.19 billion by...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Awards

Techworld Awards Winners 2011


Learn who the winners of this year's Techworld Awards are. Video footage coming soon...

Find out more
Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

Site Map

* *