Nine new patches from Microsoft

But company leaves one hole open.

Microsoft has delivered six security updates to patch nine vulnerabilities. Although the patches fix two bugs now being used by hackers but leave one still open to exploit.

Of the six bulletins, three patched some part of Windows, while the remainder plugged holes in Publisher, Internet Security and Acceleration Server (ISA), and Microsoft's virtualisation software. Six of the nine bugs were ranked critical, Microsoft's highest ranking in its four-step score, while three were tagged as "important," the next-lowest label.

"We got what we expected," said Andrew Storms, director of security operations at nCircle Network Security. "We got the 'kill bit' we were looking for in the ActiveX control, and the DirectShow fix," he said, referring to two recent vulnerabilities that attackers have been exploiting for weeks.

In May, Microsoft acknowledged ongoing attacks exploiting a bug in DirectShow, one of the components in Windows' DirectX graphics platform. Last week, it owned up to a bug in a video streaming ActiveX control used by Internet Explorer (IE), which it had known about - but not fixed - for the past 18 months. Last Thursday, Microsoft had gone into unusual detail to describe the upcoming patches, and promised that both the DirectShow and ActiveX bugs would be patched.

Microsoft also delivered patches today for two critical vulnerabilities in a Windows' font engine, and one important bug each in Publisher 2007, ISA 2006, and the client and server editions of its virtualization software.

"MS09-029 and MS09-030 are bucking the trend," said Storms, talking about two of the six bulletins released today. "Typically, Microsoft's newer software is more secure, but that's not the case here."

The fix for the Embedded OpenType (EOT) Engine in MS09-029 is rated critical in all versions of Windows, including Vista and Server 2008, which if not immune from many attacks, are often less threatened by exploits because of additional security measures baked into those operating systems. And the Publisher patch in MS09-030 fixes a file format flaw in the newest 2007 edition.

"The fact that we got them both in the same month is probably just a coincidence," said Storms, "but it doesn't surprise me that researchers are looking at the newer software, because it's the newer software that's being deployed."

Missing from today's batch was a patch or automated "kill bit" solution for another ActiveX control vulnerability that Microsoft disclosed only yesterday. web attacks exploiting that bug are rapidly increasing, but Microsoft said that it wouldn't be able to wrap up a fix in time for today.


What are your views on this subject? Use the form below to post a comment on this article up to 500 characters.


Characters remaining: 500

Related Security news

Antivirus programs fail to stop new malware

One in three systems infected.

Adobe sorry for 16-month-old Flash bug

Unpatched vulnerability 'slipped through the cracks'

HTML 5 leaves client storage open to web attacks

Security researcher says web apps could be vulnerable

Rugged Manifesto calls on developers for secure code

Security professionals call for better programming practices



Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Challenges and opportunities of PCI

The Payment Card Industry Data Security Standard provides an enterprise structure for improving operational, security, and audit performance. The benefits of the PCI DSS go beyond audit costs and results.

Download Whitepaper

Database security: Preventing enterprise data leaks at the source

IDC discusses the growing internal threats to business information, the impact of government regulations on the protection of data, and how enterprises must adopt database security best practices...

Download Whitepaper

Six essential steps to successful IT centralisation

This report, based on the real experience of a recent centralisation project, is aimed at those involved in IT strategy within their organisation. It provides some practical insights for CIOs, CTOs, Heads of IT, IT Directors and those involved more closely with the service management function.

Download Whitepaper

Application Grid: The ideal platform for IT consolidation

Evaluating the opportunity for consolidation of middleware — Java application servers and related technologies.

Download Whitepaper

Techworld UK - Technology - Business

COLT White Paper

Are all VoIP services the same?

Questions to ask your service provider to ensure you get the VoIP service you need
With careful choice of partner, your business can have all the advantages of VoIP access - reduced costs, flexibility and simplicity - without the drawbacks.
This white paper is your guide to ensure you get right the VoIP service and details the pitfalls which businesses would do well to avoid.

Download white paper
COLT White Paper

IT Misuse Survey

Complete this survey and you could win a Nexus One

Techworld are running a short survey to discover how UK businesses are managing Internet and email misuse in the Enterprise.

Complete Survey

Webcast: IT Financial Management: Cost Optimisation for Efficiency and Agility.
On Demand Webcast
Join this webcast to learn about the techniques and technologies that can help you prove the value of IT to the business by understanding the true cost of today's IT services and those that will be necessary to deliver future success.

Register Today

Site Map

IDG Network

* *