Showing posts with label Microsoft. Show all posts
Showing posts with label Microsoft. Show all posts

Wednesday, 10 July 2013

July's Patch Tuesday fixes 6 critical Microsoft flaws

If you use the Windows operating system, or just about any of the core products offered by Microsoft, it's time to install some crucial updates. Today, Microsoft pushed out seven new security bulletins—along with their accompanying patches—as well as a new policy that affects both third-party apps and those developed by Microsoft itself.

Of the seven security bulletins, six of them are rated Critical, while the remaining one is ranked as Important. The Critical security bulletins affect Windows, Internet Explorer, Microsoft Office, Silverlight, and more. The Important security bulletin addresses a privilege elevation flaw in the Windows Defender security software, so that definitely shouldn’t be ignored.

swat bugsMicrosoft squashes a number of bugs
with seven new security bulletins.

Ross Barrett, senior manager of security engineering at Rapid7, stressed this isn't your typical Patch Tuesday announcement. “Basically everything in the core Microsoft world is affected by one or more of these; every supported OS, every version of MS Office, Lync, Silverlight, Visual Studio and .NET. It’s going to be a busy time for security teams everywhere.”

Tyler Reguly, technical manager of security research and development at Tripwire, said it can be difficult to prioritize patch deployment when almost all of them are Critical. “Luckily, there's safety in the known, so customers should patch Internet Explorer first, a common theme for Microsoft patch drops.”

That means start with MS13-055—the ever-popular cumulative patch update for the Internet Explorer web browser. Reguly feels that MS13-053 should be next in line for attention after MS13-055 because it fixes a vulnerability that is already being exploited in the wild.

Qualys CTO Wolfgang Kandek agrees that MS13-053 and MS13-055 are the top priorities, but in his mind the urgency is flip-flopped. In a blog post, Kandek believes that MS13-053 is the most crucial because it affects all versions of the Windows OS, and addresses vulnerabilities that are being actively exploited. Kandek warns, “The most likely attack vector is through end users browsing a malicious web page or opening an infected document, which results in Remote Code Execution that gives control of the affected machine to the attacker.”

Developers--including Microsoft--will have only 180 days to address critical vulnerabilities.

The other big news from Microsoft is the unveiling of a new policy that places a countdown clock on dealing with vulnerabilities. Craig Young, Tripwire security researcher, explained, “Under the new policy, any app in any of the four [Microsoft] app stores will be given 180 days to resolve reported code execution bugs. This policy applies to 3rd-party developers as well as Microsoft’s own applications and is a great addition to Microsoft’s existing policy of scanning and reviewing app submissions.”

This new policy from Microsoft is significant for businesses that rely on Microsoft platforms and devices. Six months is still a long time for a vulnerability to be in place—especially Critical or Important vulnerabilities that can potentially be exploited to execute malicious code remotely—but the policy shows Microsoft's continued commitment to security. The policy applies to all apps available through the Windows Store, Windows Phone Store, Office Store, or Azure Marketplace."

The policy does not, however, apply to vulnerabilities that are being actively exploited in the wild. Flaws that pose an imminent or ongoing threat are handled with greater urgency. According to a blog post from Microsoft, "In those cases, we’ll work with the developer to have an update available as soon as possible and may remove the app from the store earlier."

If you have Automatic Updates enabled, sit back and relax, but plan on your system rebooting at some point to finish applying all of the necessary patches. If you don’t use Automatic Updates, get cracking! You’ve got a lot of Critical patches to install.

Tony is principal analyst with the Bradley Strategy Group, providing analysis and insight on tech trends. He is a prolific writer on a range of technology topics, has authored a number of books, and is a frequent speaker at industry events.
More by Tony Bradley


View the original article here

How Microsoft is using live data to redefine the Office 'document'

Microsoft is planning an overhaul of our Office documents, weaving live data into the once-static fabric of our Word files and Excel spreadsheets. It’s a bold experiment that could kill the very definition of an Office “document”—but it could also spell the rebirth of Microsoft’s productivity suite in the age of cloud-driven collaboration.

At its Build 2013 conference in June, Microsoft evangelized tools that will enable app developers to automatically use Bing’s search capabilities in documents—for example, they might enhance a travel guide with live demographic information on Belize. And Microsoft’s new PowerBI tools, announced Monday at the company’s Worldwide Partner Conference, can import data from both public and private sources to provide more up-to-date context in documents.

Both developments reveal a sea change in the way we’ll interact with Microsoft Office in the future. In the current regime, you create an Office document, save it, and then email it to a colleague, who quite likely prints it out. Indeed, the documents we create today represent just a slice of information within a brief snapshot of time.

But all this can change once Office begins hooking into living data. Office docs won’t simply document the past: They’ll also accurately reflect the ever-changing present.

Kelly WaldherMicrosoftKelly Waldher, Microsoft

”In the past, people would send around a static spreadsheet or a static PDF, with static data,” Kelly Waldher, director of Office 365 product management for Microsoft, said in an interview. “What PowerBI offers with Office 365 are a couple of new elements: real-time updates and real-time data.”

Microsoft has connected its SQL Azure cloud database to SharePoint Online, creating shared PowerBI workspaces that partners and coworkers can access, Waldher said. With a live data source powering the document, you can be sure you’re getting the most up-to-date information—and therefore the best information to base decisions on. This model assumes that documents will no longer be printed out or archived in a dead, static format, since doing so would rob them of the contextual intelligence that live data offers.

Microsoft understands that its vision will first be enabled within business environments, where enterprise tools can make sense of big data. But it’s not hard to imagine a future where a college paper on climate change might feature an interactive map that plots average mean temperatures for various cities. With consumers increasingly turning to the cloud for data storage, people will place less value on older, static documents, and more on up-to-date responses to changing conditions. That preference could extend way beyond Microsoft, and into the greater information ecosystem as a whole.

Microsoft sees its Bing search technology as the foundation for a number of capabilities.

At Microsoft’s Build 2013 conference, Gurdeep Singh Pall, corporate vice president for Microsoft’s Information Platform & Experience group, announced “Bing as a platform,” taking what we know as Microsoft’s search engine, and making it available to developers as a third-party API. “The unbounded knowledge of the Web is now available to your applications,” Pall said.

One of the tricks Microsoft executives showed was the capability to scan a block of text for keywords—such as “Valencia, Spain”—and hotlink the text to Bing-curated data. It exemplified how we might take an otherwise static document and enrich it with the Web at large.

This past March, Microsoft launched a preview of its Data Explorer tool, which allowed users to pull data from various sources and put it into Excel documents. For example, you could tell Excel to pull a compilation of credit card complaints from data.gov, or to pull a list of World Cup winners from a Wikipedia article. By itself, that capability wasn’t terribly exciting.

MicrosoftThe number of songs we listen to and purchase has declined, data reveals.

But on Monday, Microsoft renamed Data Explorer as “Power Query,” and surrounded it with a number of equally robust tools: Power Map for geolocating data; Power Pivot for flexible data models within Excel; and Power View, which allows Excel to parse data itself and to attempt to present the most relevant views automatically. Microsoft has also developed a number of BI “live sites” where customers can interact and share data.

Microsoft corporate fellow Amir Netz did a wonderful job of putting it all in context. (Netz’s presentation is archived here; fast-forward to 4:03:05 for the BI demo.) In a demonstration that used a database of popular music as an example, Netz typed in “top rock classics” as a query. The responses were automatically sorted into a track list from the 1970s and 1980s, cross-indexed by the number of weeks each song appeared on the chart. Highlighting certain words auto-suggested other choices. Highlighting “songs,” for example, suggested a list of “albums” with the same characteristics, providing avenues for further exploration.

“When I typed ‘top rock classics,’ it understood I meant rock,” Netz said. “And when I said ‘classics,’ it understood that I meant music from a certain era—the ’70s and the ’80s—and not the 1950s.”

Asking for the number of songs by year automatically generated a line graph tracking how the number of popular songs people listened to decreased between 1970 and 2000. Netz finished up by asking PowerBI to determine the best song of all time (Jason Mraz’s “I’m Yours”) and the best artist of all time (Mariah Carey). This assessment was based on what the database “knew” about each artist. Netz finished with a “king of the hill” visualization that tracked which artist dominated during which year.

”It is the beginning of a conversation with PowerBI,” Netz said, as he input a query into the search box.

MicrosoftMadonna ruled 1987 in this “king of the hill” visualization.

If Microsoft’s vision takes hold, static documents loaded with static data will seem increasingly irrelevant as time goes by. Imagine a PDF from your travel agency that answers the basic question, “What are the best countries for me to visit in Europe and the Middle East for a summer vacation?” In today’s version of the document, the answers are fixed. But we should be able to ask that query at any time, and receive answers that reflect a multitude of variables—exchange rates, hotel availability, weather, and political stability.

MicrosoftAre natural-language queries the future of data interaction?

We already live in a world where the living Web and other information sources dynamically respond to changing conditions. Take, for example, the Max tool from Netflix, which asks you questions to determine which movie you want to view. The Netflix database constantly updates itself with new movie titles, and uses information gleaned from everyone’s user searches to make other recommendations.

So at what point will traditional Office “documents”—spreadsheets, Word documents, and the like—begin to go away, victims of their own irrelevance? We don’t need to store Word documents that list the 20 bands that have the most number one hits, because that information is already stored in a database somewhere. But we will store our own analyses that machines can’t provide: the fable of Beowulf and Grendel analyzed in a historical context, for example.

If Microsoft’s vision of live, connected files becomes reality, the document of tomorrow could evolve into a framework, a predefined query. We may not know what the 100 highest-grossing movies of 2010 through 2020 will be, but we can create a document that’s preformatted to access that information—and to do so in a way that will let us quickly determine whether a sequel is primed for box-office success.

If that happens, seemingly disparate technologies—Office, Bing, and Azure—will become more closely tied to one another. And what we mean by “documents” will move far beyond today’s traditional definition.

As a result, live data sources will serve as increasingly tangible barriers that prevent data from migrating off of Office to other platforms. Indeed, while Google Apps and Apple’s iWork might let you open Microsoft’s PowerPoint format, you may not find the same level of support for Microsoft’s highly involved living-data technologies. For business users, at least, it may pay to remain under Microsoft’s umbrella.


View the original article here

Patch Tuesday: Malicious fonts bedevil Microsoft Windows

Of the six critical security bulletins Microsoft issued in its Patch Tuesday monthly release of software updates, three address a vulnerability in how Microsoft software renders fonts.

"Fonts have become really complicated," said Wolfgang Kandek, chief technology officer for compliance and security software company Qualys. "There is real processing going on when you print a character, and that complexity can be attacked."

The number of critical bulletins Microsoft released this month is a bit higher than normal, Kandek said. Typically, Microsoft will issue about two or three critical bulletins on Patch Tuesday, which occurs on the second Tuesday of each month. This month half the bulletins -- MS13-052, MS13-053 and MS13-054 -- address how Microsoft systems handle the rendering of TrueType fonts.

With this vulnerability, an attacker can embed malicious values in a font description that would overrun the memory allocated to the font-drawing routine, and write into sections of memory reserved for other operations. The font instructions could be provided to Windows or Internet Explorer (IE) by way of a Web page or a document.

"Depending on where this happens, this can be quite serious," Kandek said.

Windows, for instance, renders all characters onto the screen as a system user, not as a standard user, which has fewer system privileges. An exploit of a font-rendering vulnerability could "go right into the operating system and take control at that level," Kandek said.

Overall, Microsoft issued six critical bulletins, covering Windows OS, the .NET Framework, Silverlight, Office, Visual Studio, Lync and IE. A seventh bulletin, labeled as important, covers the Windows Defender security software.

All six of the critical bulletins include remote code execution vulnerabilities, which can be used to provide attackers with illicit access to machines.

Seventeen of the 34 vulnerabilities covered in the bulletins address IE. "Researchers continue to find flaws in IE, and the attack surface is pretty big," Kandek said, referring to how Microsoft is now supporting five different versions of the browser. The vulnerabilities affect IE versions six through 10 that run on Windows XP, Windows Vista, Windows 7, Windows 8, Windows Server 2003, Windows Server 2008 and Windows RT.

"The major problem there is that users or companies still maintain old versions of the browser. We would be better off if everyone was on the newer version" of IE, Kandek said.

One Windows vulnerability, which affects memory management, has already been publicly revealed, and has been used for an exploit that can run on the Metasploit penetration testing software. Security researchers are urging administrators to update their own versions of Windows XP, Windows Vista, Windows 7, Windows 8 and Windows 2008, Windows 2012 and Windows RT as soon as possible.

"July is one of the uglier releases we've seen from Microsoft this year. To say that all Microsoft products are affected and everything is affected critically is not an overstatement," wrote Lumension security and forensic analyst Paul Henry in an email statement. "It's difficult to prioritize one or two because all the bulletins likely need your attention this Patch Tuesday."

In addition to Microsoft patches, administrators should also take a look at Adobe's monthly set of patches, also released Tuesday. They cover vulnerabilities in Adobe Flash, Shockwave and ColdFusion, which is server-side software for rendering websites.

Joab Jackson covers enterprise software and general technology breaking news for The IDG News Service. Follow Joab on Twitter at @Joab_Jackson. Joab's e-mail address is Joab_Jackson@idg.com

Joab Jackson covers enterprise software and general technology breaking news for the IDG News Service.
More by Joab Jackson


View the original article here

Microsoft to pull apps with critical vulnerabilities

In a bid to purge insecure software from the Windows Store, Microsoft Tuesday announced that it would remove apps that it deems to have critical vulnerabilities.

Within 180 days, Microsoft said, those apps must either be patched or they will be removed.  And if an insecure app is being exploited in the wild, it risks getting pulled even sooner, executives said. The policy will also be extended to apps found in the Windows Phone Store, Office Store, and Azure Marketplace.

Microsoft outlines the vulnerabilities found within its own software, publishing the a list on the second Tuesday of each month, when it issues patches. But with the launch of Windows 8 and Windows RT, the Windows Store has become an important clearinghouse for distributing apps, and Microsoft has become more of a gatekeeper.

“We want our customers to know that, if there’s a problem, we’ll be working on a solution,” wrote Dustin Childs, the Group Manager for Response Communications for Microsoft Trustworthy Computing, a blog post outlining the seven patches that Microsoft announced last week.  “But there are some things that can affect your computing experience that I can’t directly control. For example, we can’t directly update third-party apps that you install from the Windows Store if they have a problem. But we can influence when they get updated.”

Jared NewmanIf these apps are found to have vulnerabilities, they will be pulled from the Windows Store, Microsoft said Tuesday.

In certain cases, developers will receive more than 180 days to fix their apps, but those are special cases and will be handled on an individual basis, Childs wrote.

Microsoft released seven security bulletins on Tuesday, addressing 34 vulnerabilities in Microsoft Windows, Internet Explorer, .NET Framework, Silverlight, GDI+, and Windows Defender.

Microsoft highlighted two: a Critical security update for Internet Explorer that patches 17 different issues, including a vulnerability that could allow remote code execution if a customer views a specially-crafted Web page; and a Windows kernel vulnerability that could allow remote code execution if a user opens a specially crafted document or visits a malicious webpage that embeds TrueType font files, Microsoft said.

The IE issues were privately communicated to Microsoft and have not been exploited; however, the kernel issues have been used in “limited, targeted attacks,” the company said.

Microsoft has published a full list of the most recent security bulletins here.

With Windows 8, users must manually visit the Windows Store to update apps. With Windows 8.1, Microsoft will issue app updates in the background.


View the original article here

Microsoft kicks back $5-$10 to resellers who peddle select Windows 8 hardware

Starting this week, Microsoft will give resellers up to $10 for each device they sell from a list of 21 Windows 8 touch-enabled PCs and tablets, company executives said.

The new program is the latest move by Microsoft to kick up sales, which on the PC side have been downright depressing. Research firm IDC, for instance, has forecast a decline of nearly 8 percent for 2013, and has already hinted that the drop may be even steeper. In tablets, Microsoft has had little luck in making much of an inroad into a market dominated by operating systems built by rivals Apple and Google.

But the selective nature of the incentive program—fewer than two dozen different devices qualify—shows it’s also a continuation of a strategy Microsoft has used since last summer’s launch of the Surface line, when the company said it entered the hardware business to have a platform that really flaunted Windows 8.

Both Tami Reller, the CFO of the Windows division, and Jon Roskill, who heads the firm’s global partner group, talked up the new program, dubbed “TouchWins,” at Microsoft’s Worldwide Partner Conference (WPC) Monday.

“The whole idea is to provide incentives for the commercial channel for featured devices and tablets, PCs and tablets, and through this program we will provide incentives directly to authorized distributors, as well as reseller partners, who sell featured PCs and tablets that have Windows [8] Pro and are touch-enabled,” said Reller during the day’s keynote.

Among Microsoft’s U.S.-based authorized OEM distributors are big-name sellers like Ingram Micro and ASI. Resellers run the size gamut from tiny consultancies to huge outfitters such as CDW.

Later in the presentation, Roskill characterized TouchWins as “pouring gasoline on that touch fire” as he stood in front of a screen that pegged the program’s per-device incentives between $5 and $10.

Twenty-one devices from nine OEMs—Acer, Asus, Dell, Fujitsu, HP, Lenovo, Samsung, Sony and Toshiba—have been tagged as eligible for the cash-back incentives. Acer, for example, sported three qualifying devices: the Aspire S7 touch-based “ultrabook,” which lists for $1,300; and the Iconia W5 and Iconia W7 tablets that sport screens of 10.1-in. and 11.6-in., respectively.

(Each vendor’s eligible devices can be found by clicking on the company logos here.)

The low number of qualifying devices puts TouchWins in the same general category as the Surface and Microsoft’s Signature class of “crapware”-free PCs. Like those lines, TouchWins pushes systems Microsoft believes parade Windows 8’s capabilities. It’s just one more attempt to put the OS’s best possible foot forward, said analyst Carolina Milanesi of Gartner.

TouchWins could also be seen as a stop-gap move, one that takes the best Windows 8 devices available now if, as Milanesi and other analysts expect, by this fall OEMs will have moved to newer processors that deliver much longer battery life—one of the biggest criticisms of current hardware running Windows 8 Pro.

Already-enrolled partners can jump onto the TouchWins program immediately, said Roskill, while others will be able to sign up later this summer.

Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news.
More by Gregg Keizer, Computerworld


View the original article here

Patch Tuesday: Malicious fonts bedevil Microsoft Windows

Of the six critical security bulletins Microsoft issued in its Patch Tuesday monthly release of software updates, three address a vulnerability in how Microsoft software renders fonts.

"Fonts have become really complicated," said Wolfgang Kandek, chief technology officer for compliance and security software company Qualys. "There is real processing going on when you print a character, and that complexity can be attacked."

The number of critical bulletins Microsoft released this month is a bit higher than normal, Kandek said. Typically, Microsoft will issue about two or three critical bulletins on Patch Tuesday, which occurs on the second Tuesday of each month. This month half the bulletins -- MS13-052, MS13-053 and MS13-054 -- address how Microsoft systems handle the rendering of TrueType fonts.

With this vulnerability, an attacker can embed malicious values in a font description that would overrun the memory allocated to the font-drawing routine, and write into sections of memory reserved for other operations. The font instructions could be provided to Windows or Internet Explorer (IE) by way of a Web page or a document.

"Depending on where this happens, this can be quite serious," Kandek said.

Windows, for instance, renders all characters onto the screen as a system user, not as a standard user, which has fewer system privileges. An exploit of a font-rendering vulnerability could "go right into the operating system and take control at that level," Kandek said.

Overall, Microsoft issued six critical bulletins, covering Windows OS, the .NET Framework, Silverlight, Office, Visual Studio, Lync and IE. A seventh bulletin, labeled as important, covers the Windows Defender security software.

All six of the critical bulletins include remote code execution vulnerabilities, which can be used to provide attackers with illicit access to machines.

Seventeen of the 34 vulnerabilities covered in the bulletins address IE. "Researchers continue to find flaws in IE, and the attack surface is pretty big," Kandek said, referring to how Microsoft is now supporting five different versions of the browser. The vulnerabilities affect IE versions six through 10 that run on Windows XP, Windows Vista, Windows 7, Windows 8, Windows Server 2003, Windows Server 2008 and Windows RT.

"The major problem there is that users or companies still maintain old versions of the browser. We would be better off if everyone was on the newer version" of IE, Kandek said.

One Windows vulnerability, which affects memory management, has already been publicly revealed, and has been used for an exploit that can run on the Metasploit penetration testing software. Security researchers are urging administrators to update their own versions of Windows XP, Windows Vista, Windows 7, Windows 8 and Windows 2008, Windows 2012 and Windows RT as soon as possible.

"July is one of the uglier releases we've seen from Microsoft this year. To say that all Microsoft products are affected and everything is affected critically is not an overstatement," wrote Lumension security and forensic analyst Paul Henry in an email statement. "It's difficult to prioritize one or two because all the bulletins likely need your attention this Patch Tuesday."

In addition to Microsoft patches, administrators should also take a look at Adobe's monthly set of patches, also released Tuesday. They cover vulnerabilities in Adobe Flash, Shockwave and ColdFusion, which is server-side software for rendering websites.

Joab Jackson covers enterprise software and general technology breaking news for The IDG News Service. Follow Joab on Twitter at @Joab_Jackson. Joab's e-mail address is Joab_Jackson@idg.com

Joab Jackson covers enterprise software and general technology breaking news for the IDG News Service.
More by Joab Jackson


View the original article here

Microsoft to pull apps with critical vulnerabilities

In a bid to purge insecure software from the Windows Store, Microsoft Tuesday announced that it would remove apps that it deems to have critical vulnerabilities.

Within 180 days, Microsoft said, those apps must either be patched or they will be removed.  And if an insecure app is being exploited in the wild, it risks getting pulled even sooner, executives said. The policy will also be extended to apps found in the Windows Phone Store, Office Store, and Azure Marketplace.

Microsoft outlines the vulnerabilities found within its own software, publishing the a list on the second Tuesday of each month, when it issues patches. But with the launch of Windows 8 and Windows RT, the Windows Store has become an important clearinghouse for distributing apps, and Microsoft has become more of a gatekeeper.

“We want our customers to know that, if there’s a problem, we’ll be working on a solution,” wrote Dustin Childs, the Group Manager for Response Communications for Microsoft Trustworthy Computing, a blog post outlining the seven patches that Microsoft announced last week.  “But there are some things that can affect your computing experience that I can’t directly control. For example, we can’t directly update third-party apps that you install from the Windows Store if they have a problem. But we can influence when they get updated.”

Jared NewmanIf these apps are found to have vulnerabilities, they will be pulled from the Windows Store, Microsoft said Tuesday.

In certain cases, developers will receive more than 180 days to fix their apps, but those are special cases and will be handled on an individual basis, Childs wrote.

Microsoft released seven security bulletins on Tuesday, addressing 34 vulnerabilities in Microsoft Windows, Internet Explorer, .NET Framework, Silverlight, GDI+, and Windows Defender.

Microsoft highlighted two: a Critical security update for Internet Explorer that patches 17 different issues, including a vulnerability that could allow remote code execution if a customer views a specially-crafted Web page; and a Windows kernel vulnerability that could allow remote code execution if a user opens a specially crafted document or visits a malicious webpage that embeds TrueType font files, Microsoft said.

The IE issues were privately communicated to Microsoft and have not been exploited; however, the kernel issues have been used in “limited, targeted attacks,” the company said.

Microsoft has published a full list of the most recent security bulletins here.

With Windows 8, users must manually visit the Windows Store to update apps. With Windows 8.1, Microsoft will issue app updates in the background.


View the original article here