Welcome | Sign In
MacNewsWorld.com
Security

Microsoft Patch Reflects Continuing IE Vulnerability

Print Version
E-Mail Article
Reprints
Microsoft Patch Reflects Continuing IE Vulnerability

Microsoft released seven patches for several vulnerabilities, including two zero-day flaws in Windows Media Player and a hole in Visual Studio 2005. The update does not address the recent zero-day vulnerabilities in Microsoft Word, but does resolve problems found in IE Versions 5 and 6 (Service Pack 1) running on Windows 2000, Windows XP and Windows Server 2003 systems.


Microsoft (Nasdaq: MSFT) has released seven patches for several of its applications, including Outlook Express and Visual Studio 2005. Two of the patches are rated "critical": a vulnerability in script error handling and a vulnerability in Windows Media Player.

The first patch addresses a number of vulnerabilities in Internet Explorer. "It is significant because we are seeing more hackers use these vulnerabilities for attacks," Oliver Friedrichs, director, Symantec (Nasdaq: SYMC) Security Response, told TechNewsWorld. "Simply by visiting a malicious Web site, a user could conceivably become infected."

The patch release also addresses the increase in exploitation of zero-day vulnerabilities.

Client-Side Vulnerabilities

Specifically, the patch addresses a client-side code execution vulnerability caused by a memory corruption condition when handling script errors in certain circumstances, Symantec said. It exists in Internet Explorer 5 and 6 (Service Pack 1) on Windows 2000, Windows XP and Windows Server 2003 systems.

The Windows Media Player vulnerability is also an important fix; increasingly, hackers use movie files, MP3s and other media types as hiding places for malicious code, Friedrichs said.

This client-side code execution vulnerability is caused by an unchecked buffer in Windows Media Player code that handles Advanced Streaming Format (ASF) files, Symantec explained. It affects all versions of Windows Media Player: 6.4, 7.1, 9 and 10.

The larger story from this latest patch release is that client-side vulnerabilities are not going way anytime soon, according to Friedrichs. "They are very efficient and easy for hackers to exploit," he said.

Friedrichs was not surprised that Microsoft did not release a patch for the recent, high-profile vulnerabilities in Microsoft Word. "A patch at minimum would take 28 or so days to develop," he noted.

Tips for IT Managers

Symantec offers the following advice for IT shops:

  • Evaluate the possible impact of these vulnerabilities to critical systems;
  • Plan for required responses, including patch deployment and implementation of security best practices using the appropriate security solutions;
  • Take proactive steps to protect the integrity of networks and information;
  • Verify that appropriate data backup processes and safeguards are in place and effective;
  • Remind users to exercise caution in opening any unknown or unexpected e-mail Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse attachments, or in clicking on Web links from unknown or unverified sources; and
  • Regularly run Microsoft Update and install the latest security updates.


Print Version E-Mail Article Reprints More by Erika Morphy


More by Erika Morphy

Windows 7 Flies Off the Shelves
November 06, 2009
Early sales figures on Windows 7 boxed software suggest a high level of consumer enthusiasm for the OS. Unit sales were a whopping 234 percent higher than Vista's out of the gate. The revenue haul was not as impressive, as Microsoft offered sharp discounts to spur presales. Also, sales of PCs with Windows 7 preinstalled have been lackluster -- but October is historically a weak month for PC sales.
Southwest Doesn't Fool Around
November 06, 2009
Either Southwest Airlines had better deals for my favorite route than its competitors or its superior Web site tools made it easier for me to ferret them out. Either way, kudos to Southwest. In the not-so-hot department were the airline's long list of what passengers weren't allowed to do and its very short list of what Southwest was obliged to do for them. Left me feeling a little chilly.
Commerce Search Puts Google Inside Retailers' Catalogs
November 05, 2009
Google has launched a new cloud-based search tool targeting enterprise-level e-commerce operations, just in time for the 2009 holiday selling season. Commerce Search provides a set of features designed to improve the relevance of results for consumers searching a retailer's own product catalog, while boosting cross-selling opportunities.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network