Tag Archives: Patch Tuesday

Microsoft's April Patch Tuesday brings no Pwn2Own fix

System administrators and IT security pros can take bit of a breather: Microsoft has issued a comparatively light set of patches for this edition of its monthly release of software vulnerability fixes.

“It’s a boring Patch Tuesday this month, and that’s an excellent thing for IT security teams because there won’t be a mad dog rush to get this month’s patches deployed,” wrote Andrew Storms, director of security operations for security firm nCircle, in an email statement.

Perhaps the most surprising aspect of this month’s issuance of patches was a high profile vulnerability that did not get covered. Many expected Microsoft to fix the Pwn2Own Internet Explorer bug unearthed earlier this year during a hacker contest, but such a fix was not included in this round. “This puts them quite a bit behind other browsers that already patched their Pwn2Own bugs,” Storms noted.

Overall, Microsoft issued nine bulletins, covering 14 vulnerabilities. In contrast, the company fixed 20 vulnerabilities in March, and 57 in February.

To read this article in full or to leave a comment, please click here

…read more

Source: FULL ARTICLE at PCWorld

Patch Tuesday leaves Internet Explorer zero day untouched

It’s Patch Tuesday time again. This month Microsoft has unleashed nine new security bulletins. Nine is a reasonably high number of updates, however, only two of them are rated as Critical. So, it’s actually a little more laid back than most months, but there’s still cause for concern.

There are seven security bulletins rated as Important, which affect a range of platforms and services including Active Directory, the Windows antimalware client, and the Windows Kernel. The two Critical security bulletins apply to Internet Explorer and Remote Desktop. Be prepared—most of the patches require a reboot.

Wolfgang Kandek, CTO of Qualys, suggests that IT admins focus on Internet Explorer first. “This month, the most important bulletin to apply to your infrastructure is MS13-028, which contains a new release of Internet Explorer (IE) covering all versions of the browser starting with IE6 going to IE10, and also including Windows RT, the operating system for mobile devices and tablets.”

Andrew Storms, director of security operations for nCircle (a Tripwire company), agrees that Internet Explorer deserves attention, but adds that Internet Explorer lacks its usual “patch immediately” urgency. Microsoft has assigned the underlying IE flaws with an exploit index rating of two, which indicates that Microsoft believes they are exceptionally difficult to exploit, and there’s not likely to be a successful exploit in the next 30 days.

To read this article in full or to leave a comment, please click here

…read more

Source: FULL ARTICLE at PCWorld

Prepare now to survive the end of Windows XP

The one-year countdown to the end of support for Windows XP began ticking down yesterday. If you’re still using the ancient, legacy version of Windows, it’s time to consider your next move.

To be clear, your PC will not burst into flames next year—at least, if it does, it won’t have anything to do with the expiration of Windows XP supportWhen XP support ends, Microsoft will no longer invest any resources to maintain or update it. Windows XP will still continue to work just as well as it has for the past decade.

In that case, why should you be concerned? Two words: Patch Tuesday.

Maybe it’s time to make a move to Windows 8?

When support for Windows XP ends, Microsoft will cease developing security patches for the venerable OS. As old and great as the OS is, new vulnerabilities impact Windows XP on a regular basis—including many critical flaws that could allow an attacker to take over or cripple a PC running it.

To read this article in full or to leave a comment, please click here

…read more

Source: FULL ARTICLE at PCWorld

Microsoft will auto-install Windows 7 SP1 on consumer PCs starting Tuesday

Microsoft said it will start automatically pushing Windows 7 Service Pack 1 (SP1) to customers Tuesday as a last-ditch move before it drops the original 2009 edition of Windows 7 from support next month.

Windows 7 RTM—the latter stands for “release to manufacturing,” Microsoft-speak for a launch edition—will be retired from support, including security updates, after April 9, next month’s regularly-scheduled Patch Tuesday.

Although Microsoft has made Windows 7 SP1 available via Automatic Updates—Windows’ default consumer update service—for more than two years, customers were required to approve the new version before it installed.

As of tomorrow, any Windows RTM-powered consumer PC with Automatic Updates enabled will receive Windows 7 SP1, said Microsoft in a Monday blog.

To read this article in full or to leave a comment, please click here

…read more
Source: FULL ARTICLE at PCWorld

Scary flaw makes your USB ports a major security risk

It’s the second Tuesday in March, which means that it’s also the third Patch Tuesday of 2013. Microsoft released seven new security bulletins today, with four rated as “critical,” but security experts are particularly concerned about a flaw rated as merely “important” that exposes your Windows PCs to major risk.

Wolfgang Kandek, CTO of Qualys, notes in a blog post that the number of security bulletins is about par for the course for Microsoft. He adds, “In technical terms though we are seeing some interesting vulnerabilities that definitely rate higher-than-average.”

For starters, there is a cumulative security update for Internet Explorer (MS13-021). It addresses nine separate vulnerabilities, one of which has had exploit code circulating in the wild for the past month. Kandek urges IT admins to apply this update as soon as possible.

“Every supported version of Internet Explorer (6 through 10) is affected, thus implicitly making all supported Windows platforms (including Windows RT) a target for attackers,” points out BeyondTrust CTO Marc Maiffret.

To read this article in full or to leave a comment, please click here

…read more
Source: FULL ARTICLE at PCWorld

Microsoft patch targets Internet Explorer drive-by attacks

Internet Explorer vulnerabilities warrant notice in this month’s set of Microsoft Patch Tuesday bulletins and need to be fixed quickly even though the sheer number of patches may seem daunting.

The weaknesses leave users open to drive-by attacks where malicious code is downloaded without the user’s knowledge while browsing. Not patching them because they are time-consuming will just widen the window of opportunity hackers have to exploit them, says Alex Horan, a senior product manager at CORE Security.

“Preventing future drive-by style attacks and protecting end-users appear to be the theme of this month’s Patch Tuesday,” Horan says. “These patches can be a hassle for users to deploy and have the potential to create a long enough delay where hackers can take advantage.”

So far the weaknesses haven’t been exploited. “Fortunately, this issue has no known attacks in the wild,” says Paul Henry, a security and forensic analyst at Lumension. “However, you should still plan to patch this immediately. ”

To read this article in full or to leave a comment, please click here

…read more
Source: FULL ARTICLE at PCWorld

Microsoft unleashes a Patch Tuesday to make your head spin

It doesn’t break the record for most vulnerabilities patched, or even the most security bulletins in a single Patch Tuesday, but Microsoft comes pretty close. For the February 2013 Patch Tuesday, Microsoft has a whopping 12 security bulletins, which fix a mind-numbing 57 separate flaws.

Paul Henry, security and forensic analyst at Lumension, says, “It’s going to be a rough Valentine’s Day for many IT admins this month. With ongoing issues with Java and 12 bulletins from Microsoft, including 5 critical issues and many restarts, it’s going to be a very disruptive Patch Tuesday.”

Microsoft released 12 security bulletins for
the February 2013 Patch Tuesday

Senior Manager of Security Engineering, Ross Barrett, senior manager of security engineering for Rapid7, on the other hand, tries to stay positive. “On the plus side, none of the issues patched this month are known to be actively being exploited “in the wild”.”

That is definitely good news, but IT admins still have their work cut out for them. Henry notes, “It’s disturbing to note how many different Microsoft platforms are critically affected this month. Everything from Windows XP to the new Windows RT is critically impacted.”

To read this article in full or to leave a comment, please click here

…read more
Source: FULL ARTICLE at PCWorld

Adobe patches critical flaws in Flash, Reader, and Acrobat

Today is the second Tuesday of January—which makes it the first Patch Tuesday of 2013. Adobe is addressing a few critical vulnerabilities in its software as well this Patch Tuesday.

Adobe issued two Security Bulletins. The first, APSB13-01, is for Adobe Flash. The bulletin states that versions of Adobe Flash Player for Windows, Mac OS X, Linux, and Android are all impacted by a vulnerability that could cause a system crash, or allow an attacker to execute malicious code remotely.

Adobe issued an update to patch critical flaws in Flash Player.

APSB13-02deals with flaws in Adobe Acrobat and Adobe Reader. According to the bulletin, Adobe Acrobat and Reader 11.0.0 and earlier versions on Windows and Mac OS X, and Adobe Reader 9.x versions for Linux are at risk. Like the Flash security bulletin, this one states that the vulnerabilities could lead to a system crash or allow an attacker to take control of the affected system.

To read this article in full or to leave a comment, please click here

Source: FULL ARTICLE at PCWorld

Word vulnerability tops Microsoft’s targets for Patch Tuesday

A flaw in Microsoft Word ranks among the top security problems addressed by December’s Patch Tuesday fixes, closing a hole that allows remotely executing malicious code on targeted machines regardless of whether users open the infected file. The bulletin is one of five marked critical by Microsoft in its advanced notification about vulnerabilities this month, and several security experts say the Word vulnerability is the top priority.

HELP: 11 (FREE!) Microsoft tools to make life easier 

FIRST LOOK: Surface RT 

“In this case we assume the ‘critical’ rating comes from Outlook, which can be configured to use Word to visualize documents in its preview pane,” says Qualys CTO Wolfgang Kandek. “This is an automatic mechanism that does not require user interaction. In any case, this will be an important bulletin to watch out for.”
To read this article in full or to leave a comment, please click here
Source: PCWorld