Software // Operating Systems
News
2/10/2009
04:22 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%
Repost This

Microsoft Patch Tuesday Brings Four Fixes For Eight Flaws

The updates address vulnerabilities in Internet Explorer, Microsoft Exchange, SQL Server, and Visio.

As part of its February patch cycle, Microsoft on Tuesday released four security bulletins addressing eight vulnerabilities in its software.

Two of the bulletins are designated "critical" and two are designated "important." They aim to fix vulnerabilities in Internet Explorer, Microsoft Exchange, SQL Server, and Visio.

  • MS09-002 (maximum severity of critical): This update resolves two newly discovered and privately reported vulnerabilities in Internet Explorer that could allow remote code execution if a user views a specially crafted Web page using Internet Explorer.
  • MS09-003 (maximum severity of critical): This update resolves two newly discovered and privately reported vulnerabilities in Microsoft Exchange. The first vulnerability could allow remote code execution and the second could allow denial of service.
  • MS09-004 (maximum severity of important): This update resolves a newly discovered and privately reported vulnerability in SQL Server, which could allow remote code execution if untrusted users access an affected system or if a SQL injection attack occurs to an affected system.
  • MS09-005 (maximum severity of important): This update resolves three newly discovered and privately reported vulnerabilities in Microsoft Office Visio that could allow remote code execution if a user opens a specially crafted Visio file.

Microsoft also released Security Advisory 960715, which updates a set of previously published ActiveX kill bits. The new kill bits follow from Microsoft security bulletin MS08-070 and affect Akamai Download Manager and Research in Motion AxLoader.

Eric Schultze, CTO of Shavlik Technologies, considers MS09-004 to be the most interesting patch this month. "This patch addresses the zero-day SQL Server flaw reported by Sec-Consult" on Dec. 9, he said in a statement. "This flaw enables attackers to execute code of their choice on the affected SQL Server. The bar for exploitation is raised slightly in that the attacker must already have authenticated access to the SQL Server in order to pull off this exploit."

Because proof-of-concept exploit code for this vulnerability has been published already, Schultze suggests MS09-004 ought to be rated "critical." He advises patching MS09-003 and MS09-004 as soon as possible; MS09-002 and MS09-005, he says, can wait until a more convenient time.

Paul Zimski, VP of market strategy for Lumension, argues that MS09-002, the Internet Explorer patch, also needs to be dealt with right away. "The remote code execution vulnerabilities exist in IE7 on both Windows XP and Windows Vista -- probably the most prevalent Windows configurations in use today," he said in a statement. Microsoft, he added, gives this vulnerability a score of one on its Exploitability Index, meaning that exploit code can be created easily.

A recent report argues that Microsoft should make its operating system open source, pay more attention to cloud computing, and get out of search. Download "Overhauling Microsoft" to find out why (registration required).

Comment  | 
Print  | 
More Insights
Register for InformationWeek Newsletters
White Papers
Current Issue
InformationWeek Elite 100 - 2014
Our InformationWeek Elite 100 issue -- our 26th ranking of technology innovators -- shines a spotlight on businesses that are succeeding because of their digital strategies. We take a close at look at the top five companies in this year's ranking and the eight winners of our Business Innovation awards, and offer 20 great ideas that you can use in your company. We also provide a ranked list of our Elite 100 innovators.
Video
Slideshows
Twitter Feed
Audio Interviews
Archived Audio Interviews
GE is a leader in combining connected devices and advanced analytics in pursuit of practical goals like less downtime, lower operating costs, and higher throughput. At GIO Power & Water, CIO Jim Fowler is part of the team exploring how to apply these techniques to some of the world's essential infrastructure, from power plants to water treatment systems. Join us, and bring your questions, as we talk about what's ahead.