Top Security News

Ernst and Young Release Annual Security Survey
Ernst and Young have released their annual security survey, and the findings are in line with other similar surveys this year...

Deworming The Globe Of Windows 2000
It's been several years since Windows 2000 finally arrived as a replacement for Windows NT and Windows 98...

Real Media Files Owned By Virus
McAfee's Avert Labs has discovered a virus in the wild, W32/Realor...

FTC Pops The Clutch On Media Motor
Notorious PC hijacker software Media Motor had its doors blown off by the Federal Trade Commission, which persuaded a US District Court to shut down its distributors...

Legal Drivers, Cost Implications for Information Security
Do the new laws really help information security, and raise the general overall level of security or are they just things to follow along with when being audited...

Jim Hurley Has Noted Your Compliance
The former Aberdeen Group VP now works as managing director of the IT Policy Compliance Group founded by Symantec, the Computer Security Institute (CSI), and the Institute of Internal Auditors (IIA); we talked about the group's recent study of factors that...


David A. Utter
Tuesday:11.21.06

Patch Tuesday Is Exploit Tuesday Too


Security researchers have been reporting newly found vulnerabilities on the same day Microsoft releases its monthly slate of patches, in an apparent effort to gain more notice.

Exploits of just-patched vulnerabilities have been cropping up on sites like SecurityFocus and Secunia on the same days Microsoft releases patches for those flaws. That was the observation of McAfee researcher Karthik Raman, who posted about this on McAfee's Avert blog.

Raman noted this vulnerability in Microsoft's Windows 2000 products' Active Directory appeared on November 14th. That was the most recent release of patches from Microsoft to its customers.

"I've called attention before to what may be a trend for vulnerability disclosure," said Raman. "Security researchers might be releasing Microsoft vulnerabilities on or just after a Patch Tuesday to maximize the vulnerabilities' window of exposure. The November 14 Windows Active Directory vulnerability is yet another curve-fitter in this trend!"

The Active Directory issue has been rated Less Critical by Secunia. It could be exploited from a local network to create a DoS condition on a targeted system. The problem has yet to be patched.

Low Rate eCommerce & Retail Plans

News of another Less Critical flaw, this time a cross site scripting issue, came out as October's patches were being released on the 10th of that month. Microsoft's patches for that day corrected the issue among others, but the company was slow to get those patches distributed to the millions of machines waiting for them.

It has been a trend, as Raman and others have observed, to crank out an exploit just as patches become available to correct known flaws. But with some third parties disclosing brand new exploitable issues on the day Microsoft releases its fixes, the company could be in for another embarrassing episode like the spread of the Sasser worm.

Microsoft does the once-a-month updates as a convenience to the thousands of system administrators who have responsibility for ensuring patches get placed on the machines they supervise. That cycle may have to be shortened, especially if the release of the Vista operating system proves just as vulnerable to issues as previous versions have.

The company has claimed, through outgoing executive Jim Allchin and others, that Vista will be the safest operating system Microsoft has delivered in its history. After January 2007, when Vista hits the home market, that will be put to the test.

About the Author:
David Utter is a business and technology writer for SecurityProNews, WebProNews, and InternetFinancialNews.



About SecurityProNews
SecurityProNews is updated in real time with vital internet security alerts, news and in-depth articles for IT Managers. SecurityProNews understands that IT Management Begins With Security.
 

SecurityProNews is brought to you by:

SecurityConfig.com NetworkingFiles.com
ITmanagementNews.com NetworkNewz.com
DatabaseProNews.com SQLProNews.com
ITcertificationNews.com SysAdminNews.com
LinuxProNews.com WirelessProNews.com
 
 

Advertising Newsletters Corporate Info Site Map Support
© 2006 SecurityProNews. An email newsletter.
, Inc. 2549 Richmond Rd. Lexington KY, 40509
All Rights Reserved. Terms under which this service is provided to you. Read our privacy policy. Contact us.
SecurityProNews is part of the iEntry Inc. Network of sites and newsletters.
SecurityProNews About Us News Archives Feedback