16 Bulletins, 34 Bugs: Another Busy Tuesday for IT Admins
After last month’s relatively light security update, Microsoft released 16 bulletins to address 34 vulnerabilities. Nine of these bulletins were tagged “critical” while the remaining seven were deemed ”important.” The patch release contains fixes for bugs in Microsoft Windows, Microsoft Office, Internet Explorer (IE), and Silverlight, among others. Most of the updates also require a system restart, making deployment a possible issue for IT administrators.
Trend Micro earlier worked with Microsoft regarding a vulnerability that was addressed in this release, specifically one found in IE (CVE-2011-1252). This vulnerability involves the way IE handles specific strings when sanitizing URLs. If exploited, this can allow cross-site scripting that can possibly lead to unauthorized information disclosure.
Microsoft also addressed the “cookiejacking” issue in this month’s release. A cookiejacking attack may allow an attacker to acquire cookies from a user’s system and access the websites that the user recently logged in to. Microsoft, however, believes this threat does not pose huge risks, considering the level of user interaction required to successfully conduct an attack.
Trend Micro Threat Research Manager Robert McArdle, on the other hand, as shown in “Contrary to Reports—Cookiejacking Presents a Major Risk,” believes that such an attack heavily uses social engineering tactics, which are often subtle, devious, and emotive, making them very successful. Hopefully, this Microsoft update Microsoft will provide more protection for users.
To keep systems protected, users are advised to visit the related Microsoft pages and to immediately download the security updates. For enterprise users, we offer specific solutions to deal with vulnerabilities. Both Deep Security and OfficeScan with Intrusion Defense Firewall (IDF) plug-in have existing rules that protect users from the vulnerabilities patched in this month’s release.
For more information about this month’s security update, read the related Threat Encyclopedia entry.
In addition, Adobe issued its own batch of security updates for this month comprising six security bulletins to address vulnerabilities in applications like Adobe Flash Player, Adobe Shockwave Player, Adobe Reader, and Adobe Acrobat. Users are also strongly advised to patch their software as soon as possible.
Post from: TrendLabs | Malware Blog – by Trend Micro
Spotlight
Cloud Computing
- Cloud security group develops third-party certification program
- US makes large investment in cyber weaponry
- Wall Street has data security concerns over Bloomberg reporting
- Security in backups means more than just encryption
Virtualization
- Virtualization-specific challenges could threaten data security
- Evolving threats put security skills in high demand
- Virtualization security requires education, access control management
- Tips for launching effective virtual security tools
Internet Safety
- Virtualization-specific challenges could threaten data security
- Evolving threats put security skills in high demand
- Virtualization security requires education, access control management
- Tips for launching effective virtual security tools
Vulnerabilities & Exploits
CTO Insights
First Line of Defense
Newsletter
Stay up to date with the latest news and information on online threats.
Recent News
- Twitter now offers two-factor authentication
- DHS needs better sharing plan, experts say
- Cloud security group develops third-party certification program
- US makes large investment in cyber weaponry
Tag Cloud
cloud cloud computing cloud computing security Cloud Security Compliance & Regulations Consumerization Current News cybercrime Data Privacy data security Encryption Government Policy Internet Protection Internet Safety Internet Safety - DO NOT USE Internet Security Malware Mobile Security Mobility Policy Policy - DO NOT USE Privacy Privacy & Policy Private Cloud Public Cloud Reports Research Spotlight threat intelligence threat research Trend Labs Underground Economy virtualization Vulnerabilities Vulnerabilities - DO NOT USE web security web threats



Comments
No comments yet