All the latest UK technology news, reviews and analysis

Microsoft patches 22 holes and three zero-day flaws

by Phil Muncaster

09 Feb 2011

Be the first to comment

  • Tweet this

Microsoft has released 12 security bulletins this month patching 22 flaws, including zero-day vulnerabilities in Windows, Internet Explorer and IIS.

February's Patch Tuesday sees three 'critical' updates in total, two for Windows and one for Internet Explorer.

The latter relates to a Cascading Style Sheet (CSS) issue and could allow remote code execution "if a user views a specially crafted web page using IE or if a user opens a legitimate HTML file that loads a specially crafted library file", according to the Microsoft Security Bulletin Summary for February 2011.

"Among the six previously public vulnerabilities fixed, the Internet Explorer CSS issue is the only one Symantec is seeing actively being used in attacks," said Joshua Talbot, security intelligence manager for Symantec Security Response.

"The attacks aren't extremely widespread, but we did recently see a spike in activity. IT managers should patch this right away, especially those that have not implemented the temporary workaround released last month."

Wolfgang Kandek, chief technology officer at vulnerability management firm Qualys, agreed that the IE update is the most important for IT managers to apply, but also highlighted the IIS flaw, which could allow remote code execution on IIS through the FTP service, and the Windows 'thumbnail' remote code execution vulnerability.

The third critical vulnerability in this month's line up addresses a flaw in the OpenType library, he added.

"Since OpenType is not used in IE, this important attack vector is closed off, forcing more complicated delivery schemes to be used - via zipped folders, for example - similar to this attack on MS11-006, " said Kandek.

"As third-party browsers can possibly be used in the exploitation of this flaw, we recommend including this patch in the high priority queue."

However, two zero-day exploits currently affecting Microsoft products have not been addressed, including the MHTML flaw that affects all versions of Windows.

"The scope and impact of the MHTML vulnerability is relatively limited compared to other recent zero-day code execution vulnerabilities," said Jim Walter, manager of the McAfee Threat Intelligence Service for McAfee Labs.

"Based on the information that is currently available, we are aware that successful exploitation could lead to the running of arbitrary scripts, as well as the disclosure of sensitive information."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

31%

1%

11%

57%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Systems Engineer

Lead/Project Engineer Microsoft VMware SAN Networking...

Application Tester

SENIOR APPLICATION TESTER. Assen, Netherlands. €1k-€1...

Project Manager - Trading Systems - up to £85'000

Project Manager - Trading Systems - up to £85'000...

SAS Senior Analyst- Direct Marketing Agency

SAS Senior Analyst- up to £55,000 Industry: Marketing...

To send to more than one email address, simply separate each address with a comma.