Showing posts with label critical. Show all posts
Showing posts with label critical. Show all posts

Wednesday, 10 July 2013

July's Patch Tuesday fixes 6 critical Microsoft flaws

If you use the Windows operating system, or just about any of the core products offered by Microsoft, it's time to install some crucial updates. Today, Microsoft pushed out seven new security bulletins—along with their accompanying patches—as well as a new policy that affects both third-party apps and those developed by Microsoft itself.

Of the seven security bulletins, six of them are rated Critical, while the remaining one is ranked as Important. The Critical security bulletins affect Windows, Internet Explorer, Microsoft Office, Silverlight, and more. The Important security bulletin addresses a privilege elevation flaw in the Windows Defender security software, so that definitely shouldn’t be ignored.

swat bugsMicrosoft squashes a number of bugs
with seven new security bulletins.

Ross Barrett, senior manager of security engineering at Rapid7, stressed this isn't your typical Patch Tuesday announcement. “Basically everything in the core Microsoft world is affected by one or more of these; every supported OS, every version of MS Office, Lync, Silverlight, Visual Studio and .NET. It’s going to be a busy time for security teams everywhere.”

Tyler Reguly, technical manager of security research and development at Tripwire, said it can be difficult to prioritize patch deployment when almost all of them are Critical. “Luckily, there's safety in the known, so customers should patch Internet Explorer first, a common theme for Microsoft patch drops.”

That means start with MS13-055—the ever-popular cumulative patch update for the Internet Explorer web browser. Reguly feels that MS13-053 should be next in line for attention after MS13-055 because it fixes a vulnerability that is already being exploited in the wild.

Qualys CTO Wolfgang Kandek agrees that MS13-053 and MS13-055 are the top priorities, but in his mind the urgency is flip-flopped. In a blog post, Kandek believes that MS13-053 is the most crucial because it affects all versions of the Windows OS, and addresses vulnerabilities that are being actively exploited. Kandek warns, “The most likely attack vector is through end users browsing a malicious web page or opening an infected document, which results in Remote Code Execution that gives control of the affected machine to the attacker.”

Developers--including Microsoft--will have only 180 days to address critical vulnerabilities.

The other big news from Microsoft is the unveiling of a new policy that places a countdown clock on dealing with vulnerabilities. Craig Young, Tripwire security researcher, explained, “Under the new policy, any app in any of the four [Microsoft] app stores will be given 180 days to resolve reported code execution bugs. This policy applies to 3rd-party developers as well as Microsoft’s own applications and is a great addition to Microsoft’s existing policy of scanning and reviewing app submissions.”

This new policy from Microsoft is significant for businesses that rely on Microsoft platforms and devices. Six months is still a long time for a vulnerability to be in place—especially Critical or Important vulnerabilities that can potentially be exploited to execute malicious code remotely—but the policy shows Microsoft's continued commitment to security. The policy applies to all apps available through the Windows Store, Windows Phone Store, Office Store, or Azure Marketplace."

The policy does not, however, apply to vulnerabilities that are being actively exploited in the wild. Flaws that pose an imminent or ongoing threat are handled with greater urgency. According to a blog post from Microsoft, "In those cases, we’ll work with the developer to have an update available as soon as possible and may remove the app from the store earlier."

If you have Automatic Updates enabled, sit back and relax, but plan on your system rebooting at some point to finish applying all of the necessary patches. If you don’t use Automatic Updates, get cracking! You’ve got a lot of Critical patches to install.

Tony is principal analyst with the Bradley Strategy Group, providing analysis and insight on tech trends. He is a prolific writer on a range of technology topics, has authored a number of books, and is a frequent speaker at industry events.
More by Tony Bradley


View the original article here

Microsoft to pull apps with critical vulnerabilities

In a bid to purge insecure software from the Windows Store, Microsoft Tuesday announced that it would remove apps that it deems to have critical vulnerabilities.

Within 180 days, Microsoft said, those apps must either be patched or they will be removed.  And if an insecure app is being exploited in the wild, it risks getting pulled even sooner, executives said. The policy will also be extended to apps found in the Windows Phone Store, Office Store, and Azure Marketplace.

Microsoft outlines the vulnerabilities found within its own software, publishing the a list on the second Tuesday of each month, when it issues patches. But with the launch of Windows 8 and Windows RT, the Windows Store has become an important clearinghouse for distributing apps, and Microsoft has become more of a gatekeeper.

“We want our customers to know that, if there’s a problem, we’ll be working on a solution,” wrote Dustin Childs, the Group Manager for Response Communications for Microsoft Trustworthy Computing, a blog post outlining the seven patches that Microsoft announced last week.  “But there are some things that can affect your computing experience that I can’t directly control. For example, we can’t directly update third-party apps that you install from the Windows Store if they have a problem. But we can influence when they get updated.”

Jared NewmanIf these apps are found to have vulnerabilities, they will be pulled from the Windows Store, Microsoft said Tuesday.

In certain cases, developers will receive more than 180 days to fix their apps, but those are special cases and will be handled on an individual basis, Childs wrote.

Microsoft released seven security bulletins on Tuesday, addressing 34 vulnerabilities in Microsoft Windows, Internet Explorer, .NET Framework, Silverlight, GDI+, and Windows Defender.

Microsoft highlighted two: a Critical security update for Internet Explorer that patches 17 different issues, including a vulnerability that could allow remote code execution if a customer views a specially-crafted Web page; and a Windows kernel vulnerability that could allow remote code execution if a user opens a specially crafted document or visits a malicious webpage that embeds TrueType font files, Microsoft said.

The IE issues were privately communicated to Microsoft and have not been exploited; however, the kernel issues have been used in “limited, targeted attacks,” the company said.

Microsoft has published a full list of the most recent security bulletins here.

With Windows 8, users must manually visit the Windows Store to update apps. With Windows 8.1, Microsoft will issue app updates in the background.


View the original article here

Microsoft to pull apps with critical vulnerabilities

In a bid to purge insecure software from the Windows Store, Microsoft Tuesday announced that it would remove apps that it deems to have critical vulnerabilities.

Within 180 days, Microsoft said, those apps must either be patched or they will be removed.  And if an insecure app is being exploited in the wild, it risks getting pulled even sooner, executives said. The policy will also be extended to apps found in the Windows Phone Store, Office Store, and Azure Marketplace.

Microsoft outlines the vulnerabilities found within its own software, publishing the a list on the second Tuesday of each month, when it issues patches. But with the launch of Windows 8 and Windows RT, the Windows Store has become an important clearinghouse for distributing apps, and Microsoft has become more of a gatekeeper.

“We want our customers to know that, if there’s a problem, we’ll be working on a solution,” wrote Dustin Childs, the Group Manager for Response Communications for Microsoft Trustworthy Computing, a blog post outlining the seven patches that Microsoft announced last week.  “But there are some things that can affect your computing experience that I can’t directly control. For example, we can’t directly update third-party apps that you install from the Windows Store if they have a problem. But we can influence when they get updated.”

Jared NewmanIf these apps are found to have vulnerabilities, they will be pulled from the Windows Store, Microsoft said Tuesday.

In certain cases, developers will receive more than 180 days to fix their apps, but those are special cases and will be handled on an individual basis, Childs wrote.

Microsoft released seven security bulletins on Tuesday, addressing 34 vulnerabilities in Microsoft Windows, Internet Explorer, .NET Framework, Silverlight, GDI+, and Windows Defender.

Microsoft highlighted two: a Critical security update for Internet Explorer that patches 17 different issues, including a vulnerability that could allow remote code execution if a customer views a specially-crafted Web page; and a Windows kernel vulnerability that could allow remote code execution if a user opens a specially crafted document or visits a malicious webpage that embeds TrueType font files, Microsoft said.

The IE issues were privately communicated to Microsoft and have not been exploited; however, the kernel issues have been used in “limited, targeted attacks,” the company said.

Microsoft has published a full list of the most recent security bulletins here.

With Windows 8, users must manually visit the Windows Store to update apps. With Windows 8.1, Microsoft will issue app updates in the background.


View the original article here