September 8, 2009 10:24 AM PDT

Microsoft issues critical Windows patches

by Ina Fried
  • Font size
  • Print
  • 36 comments

Microsoft on Tuesday issued five critical Windows-related updates as part of its monthly Patch Tuesday release.

While the issues affect different versions of Windows differently, Microsoft said none of the issues apply to the final version of Windows 7, which Microsoft wrapped up in July.

The five bulletins address eight vulnerabilities. According to Symantec Security Response research manager Ben Greenbaum, the two vulnerabilities most likely to be used by attackers involve the way Windows handles ASF and MP3 media files. "We've seen similar exploits in the past and all a user would have to do is visit a compromised Web site hosting one of these malicious files, which could be an MP3, WMA or WMV file, and they could become infected."

McAfee Avert Labs director Dave Marcus said that two of the flaws, in particular, relate to serious security vulnerabilities in the networking components of Window Vista, Windows Server 2008 and Windows Server 2003 that could allow for malicious software to spread from one PC to another.

"These vulnerabilities are the most likely to be exploited by malicious code and are two of the best worm candidates that we've seen since Conficker," Marcus said in a statement. "That said, all of today's security bulletins address vulnerabilities that could allow an attacker to take complete control of a vulnerable PC."

In addition, Microsoft said it is re-releasing a bulletin from last month to address an additional control found to be vulnerable to an issue with the Microsoft Active Template Library.

Greenbaum noted that Microsoft has yet to issue a patch for a zero-day flaw in Internet Information Services that was made public last week. "Until a patch for this is issued, as a temporary workaround we suggest IT administrators using IIS 5.0 and 6.0 turn off anonymous write access immediately," Greenbaum said. "We also recommend using a firewall and restricting access to creating directories. Those using IIS 7.0 with FTP Service version 6.0 installed should upgrade to FTP Service version 7.5."

There are already some attacks being seen based on that flaw.

"While the company will not release an update this month, it will do so once it has reached an appropriate level of quality for broad distribution," Microsoft said.

Meanwhile, Microsoft said Tuesday that it is investigating another zero-day issue, this one a reported flaw in Windows Vista and Windows 7.

As for the patches Microsoft did release on Tuesday, Qualys CTO Wolfgang Kandek noted that some of the bulletins are interesting in that they either affect only newer operating systems or are more critical on later versions--the reverse of what is normally the case. Overall, he said, five Windows patches should keep IT workers busy.

"Due to the criticality of the patches and wide coverage of the operating system, this will be a busy day for IT administrators," Qualys CTO Wolfgang Kandek said in an e-mail.

During her years at CNET News, Ina Fried has changed beats several times, changed genders once, and covered both of the Pirates of Silicon Valley. These days, most of her attention is focused on Microsoft. E-mail Ina.
Recent posts from Beyond Binary
Visual Studio launch delayed by 'a few weeks'
Glitches mar launch of Livescribe app store
Windows 7 leaving Redmond's help desk less busy
Microsoft top lawyer: EU deal opens new chapter
Microsoft: We did copy Plurk's code
Boeing's 787 takes flight
Hands-on with the Entourage Edge
Microsoft's server chief talks cloud (Q&A)
Add a Comment (Log in or register) (36 Comments)
  • prev
  • 1
  • next
by Vegaman_Dan September 8, 2009 10:50 AM PDT
Windows Automatic Updates takes care of all of the patches automatically. Sometimes it's a good thing to let those defaults work the way they are meant to.

I'm rather surprised it's only five this time though. I'm used to seeing a dozen or so total.
Reply to this comment
by Random_Walk September 8, 2009 1:52 PM PDT
"Windows Automatic Updates takes care of all of the patches automatically."

...it also has a habit of breaking things, automatically. Run it on your Exchange 2007 servers sometime... and watch your enterprise webmail and Free/Busy services go 'splat' until all the other Exchange 2k7 servers catch up to the same patch level.

...and we haven't even covered the enforced reboot habit that can cause server downtime at the most inconvenient of times. ;)
by Mark_Anderson September 8, 2009 2:53 PM PDT
Hi Penguin, any proof there?
by Vegaman_Dan September 8, 2009 2:59 PM PDT
@Random _Walk:

A competent administrator can take care of those issues readily. Microsoft does allow you to tailor the updates as you wish to have them run. It's not hard at all. Simply go to the management console. Heck, you can do it in remotely if you want. Server management simply isn't that hard to do. This is the sort of 1st year student level type of work.
by gp2792 September 8, 2009 4:56 PM PDT
Really Random? you run Windows Update on your servers??? that's pretty telling. Must have a small windows environment to not use WSUS.
by Vegaman_Dan September 8, 2009 8:19 PM PDT
@gp2792:

WSUS is for professional administrators. Remember, Random_walk isn't talking about professionals and servers. He's pointing out more like the small time operations without a dedicated system admin, I think.
by Jamasama September 9, 2009 11:16 AM PDT
Just to clarify, every OS has to restarty to apply a security patch. Just the way it works.
by WinNoMo September 8, 2009 11:18 AM PDT
Maybe someday Windows will be safe enough. Until then, I will stick with the alternatives.
Reply to this comment
by BingItOn September 8, 2009 7:52 PM PDT
What is other alternative compared to Rock Solid foundation of Windows 2008 R2 and Win , welcome to future :)
by Vegaman_Dan September 8, 2009 8:22 PM PDT
@BingItOn:

Both Linux and Apple have good products that can compete in this area. Use what works best for you.
by Gold_Storm_Mac September 8, 2009 11:27 AM PDT
no comment
Reply to this comment
by mlcgruhlke September 8, 2009 11:36 AM PDT
This is exacting why I am running Mac - Windows is nothing but a security hole.
Reply to this comment
by Mark_Anderson September 8, 2009 11:39 AM PDT
No, you're running a Mac because you're too stupid to keep up with current events.
by catch23 September 8, 2009 12:00 PM PDT
Then please explain the endless patches from Apple for security reasons.
Can't? Didn't think so
by Lennron September 8, 2009 12:37 PM PDT
I wish I had enough money to throw away on a Mac like mlcgruhlke does. Because if i did... I'd buy two Dell's for the same price with the exact same specs as the Mac. :)
by cary1 September 8, 2009 1:28 PM PDT
Excatly. With a mac, you do not have any updates. Apple never releases security updates. I am glad we are on the same page here
by Random_Walk September 8, 2009 1:56 PM PDT
Perhaps in your rush to knee-jerk out a hot and frothy defense of your object of worship (Windows), you might have missed the aspect of urgency. In OSX at this time, there is no urgency to run Software Updates.

Meanwhile, in Windowsland, there are hordes of s'kiddies happily reverse-engineering the latest fixes and looking to exploit the unpatched as soon as practical - a time-frame that has shrunk to hours in some instances (meaning, we hope you manage to patch before they find one, campers...)

Now if you don't mind, I have to test a shedload of Windows servers against this patch (thank Heaven for VMWare and 'cloning'....)
by Gold_Storm_Mac September 8, 2009 1:57 PM PDT
i havent had a mac patch in weeks.
by shycelticwitch September 8, 2009 1:58 PM PDT
LOL @ Mark. Looks to me like somebody's standing on your 'nads. Glad these things don't come with sound bytes.
by Mark_Anderson September 8, 2009 2:54 PM PDT
Thanks for proving my point about ********, witch! :)
by Vegaman_Dan September 8, 2009 3:04 PM PDT
@Random_Walk:

I'm sure glad you know more than Apple does on security. That silly company keeps releasing security updates for not only OS X but a host of other products including things like QuickTime and iTunes. But the joke's on Apple because you know better- it's pointless to run security updates on a Mac! So says Random_Walk!

Now in reality, I'm a bit more inclined to believe Apple just a wee bit more than you- I somewhat suspect they know a bit more about the product than you do, but who knows, I could be wrong. :)
by santuccie September 8, 2009 4:14 PM PDT
@Penguinisto:

'Perhaps in your rush to knee-jerk out a hot and frothy defense of your object of worship (Windows), you might have missed the aspect of urgency. In OSX at this time, there is no urgency to run Software Updates.'
>>>>In case you have forgotten, there have been a few hundred vulnerabilities reported in Windows Vista since its release. And yet, since IE8 and the latest versions of Firefox have fully implemented Vista's ASLR (and DEP, which Snow Leopard does not have, at least not properly implemented), no working exploits have been discovered.

Still using status quo as evidence for inherent security, I see. And now, you've picked up on my religious fundamentalist zingers. However, there is irony in your use of such terms. As it were, our "frothy defenses" happen to have factual foundations, while yours do not. It's because of these empty assertions that you stand accused of worshipping an operating system. Your attempt to channel it back at us doesn't work quite as well, sorry.

'Meanwhile, in Windowsland, there are hordes of s'kiddies happily reverse-engineering the latest fixes and looking to exploit the unpatched as soon as practical - a time-frame that has shrunk to hours in some instances (meaning, we hope you manage to patch before they find one, campers...)'
>>>>As always, where are the post-2007 exploits? And, as I'm sure I'll have to remind you plenty more times in the future, I'm asking for "EXPLOITS," not Trojans. And if you want to avoid looking stupid again, make sure that the exploit itself is affecting Vista machines, and not just the vulnerability. Remember, the vulnerabilities exploited by Conficker and Gumblar happen to affect Vista machines, but the worms will not work on Vista because of its mitigations.

'Now if you don't mind, I have to test a shedload of Windows servers against this patch (thank Heaven for VMWare and 'cloning'....)'
>>>>This is getting old. You're a long way from measuring up to a network administrator. If you were one, then you would know the difference between an exploit and a Trojan horse. EVERY SA I know is aware of the difference, as are most of the people in my own department.

Those past remarks of yours about Charlie Miller's "geek stick" have left your credibility in ruins; that is, whatever credibility you could possibly have built back up after falling flat on your face by signing /P under your current username. You know too little about computers, security, and hacking to continue to claim ANY technical expertise, much less the level of prestige you're trying to assume. And again, when we already know that you're not above trying to reinforce yourself by using two different usernames simultaneously, your word would continue to mire you even if you WERE a good pretender. Nice try, but no cigar. Stay in school, kid!
See more comment replies
by assman September 8, 2009 11:59 AM PDT
Predictable comments.
Reply to this comment
by Otto Holland September 8, 2009 12:46 PM PDT
Your MAC has more holes than a strainer the size of one huge mountain pass of the PA Turnpike. If you or anyone think Mac?s are that safe; you are living on another planet.

Any OS can be attacked and that goes for any flavor UNIX or LINUX as well. Being ignorant about security or too lazy to apply patches is the main cause of failure.

In enterprise computing using MS products; there must be a WSUS server that is constantly administered. This is a very small part of my job and my company has not had an attack as far as I can remember. The same should apply to all OS being used, even if they are behind a dozen firewalls.
Reply to this comment
by Dalkorian September 8, 2009 5:03 PM PDT
What kind of attacks can you make against my Media Access Controller again? I constantly find it amazing how some people have learned a few winblows GUI applications and they suddenly think they are computer admin gods or something.
by Vegaman_Dan September 8, 2009 8:33 PM PDT
@Dalkorian:

It's nearly as annoying as righteous zealots who keep harping on MAC vs Mac distinctions, assuming the world is too stupid to know the difference and that they need your help to understand the context of the message.
by shycelticwitch September 8, 2009 1:54 PM PDT
In all fairness, Snow Leopard is not without it's "opening day" problems too. Each of us uses what works best for us, in my case I need supported platforms so I choose OS X AND Windows. Yes, I run more Mac machines than PCs, but the fact of the matter is, neither does everything perfect.

@ Dan... I had to add a second Windows system as one of our new recruits is more familiar with that platform. I still prefer Mac, but don't necessarily dislike Windows. What I do dislike is someone telling me it's better simply because it commands more market share.
Reply to this comment
by Hokulea September 8, 2009 2:42 PM PDT
@shycelticwitch "What I do dislike is someone telling me it's better simply because it commands more market share."

I dislike someone telling me Macs are better simply because they have less market share, which somehow makes them more secure. I can care less what OS I use, as long as it will let me run the apps I want to.

As usual, my system updated without any problems.
by Vegaman_Dan September 8, 2009 3:07 PM PDT
@Shycelticwitch:

" I still prefer Mac, but don't necessarily dislike Windows"

Your own prior comments here on CNET would tend to cast this statement into a bit of doubt. What changed?
by Vegaman_Dan September 8, 2009 8:36 PM PDT
@ShyCelticWitch:

Let me apologize to you on that last comment. That was me being snarky and I didn't think you really meant what you said, but going back and rereading it, I think I need to delay my response a bit more before commenting.
by shycelticwitch September 10, 2009 11:02 AM PDT
Dan... duly noted. My opinions of Windows hasn't changed. I just don't express them quite as vehemently anymore. I have much better things to do with my time. I have never said that Apple was better because they had less market share. I simply stated on each occasion that over the years I have had less problems and fewer upgrades for my money with the Mac platform. Market share doesn't mean a hoot to me as long as the company itself is stable. Less market share means smaller target for those who would attack. Works well for me, and I hope it doesn't change anytime soon! : )
by wiimonkey9 September 9, 2009 12:09 PM PDT
so far on windows 7 rtm I haven't had any security problems.

.. then again I never do, maybe it is because I am not a dumb@$$ or that people don't target me :p

btw, it is my birthday, woot!
Reply to this comment
by monster_eater123 September 9, 2009 11:09 PM PDT
May I remind Windows users, running Automatic updates DOES NOT give you all the security up dates. Rather just the biggest and most important ones. Otherwise you need to go to Microsoft Update and select Custom mode and get all the updates.
Reply to this comment
(36 Comments)
  • prev
  • 1
  • next

15 sites that went kaput in 2009

Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.

Top 10 news stories of the decade

Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.

About Beyond Binary

During her years at CNET News, Ina Fried has changed beats several times, changed genders once, and covered both of the Pirates of Silicon Valley. These days, most of her attention is focused on Microsoft.


Beyond Binary is a look at how technology is changing our lives and the people behind all that life-changing stuff, with an extra emphasis on that which emanates from Redmond, Wash.

Add this feed to your online news reader

Beyond Binary topics

Binary Bits

    Follow Ina on Twitter (Twitter name: InaFried)
    advertisement
    advertisement

    Inside CNET News

    Scroll Left Scroll Right