[ insider_reports_insider ] Microsoft’s November Security Bulletin: Friend Or Foe?
John Stith Staff Writer
2005-11-09
Insider Reports RSS Feed
Microsoft sent out their new critical patch on Tuesday and it was loaded with major fixes, 3 to be specific. While this Tuesday patch has become a regular event with Microsoft, their most recent releases haven't been all that successful. In some cases, they've done as much damage as they've corrected. Is the November patch going to be more of the same?
 | | Are Microsoft's Patches Helpful or Hurtful? |  |
Microsoft released a patch back in August, skipped September and had another one for October. In both the August and October releases, major problems occurred and the fixes could wreak havoc on computers if not done absolutely properly because they involved registry changes or created vulnerabilities in the computer.
Two of the three are rated critical. One is a graphic rendering engine vulnerability (GRE); the other is a Windows Metafile (WMF) vulnerability. The third, rated as moderate, is an Enhanced Metafile (EMF) vulnerability.
The GRE problem is a remote code execution issue tied to the WMF and EMF image formats. An attacker could take control of an effected system. It would occur if the attacker somehow gained access either through file, like a picture file. Or it could work from a web page designed to exploit this vulnerability. One workaround was to view email in plain text format versus something supporting graphics.
The WMF problem is also a remote code execution issue. This is similar to the graphics rendering issue in that they are both tied to the image format of the WMF. Any program rendering WMF images is vulnerable to losing control of the affected system. The work around is the same too.
The third update, while rated moderate, shouldn't be taken too lightly. The EMF vulnerability could result in a denial of service attack by causing the affected programs to stop responding. The vulnerability, like the other two, is tied to an image format. The attacks can be circumvented in much the same manner. Read your email in plain text format.
While these problems seem fairly easy to avoid, the can cause real damage. The big question for Microsoft at this point is patch credibility. Is the new patch going to do real good or real harm? Chances are, the hacker world is already working their own ways to annoy people. It looks like this may be a no win scenario.
About the Author:
John is a staff writer for SecurityProNews covering cyber security.
More insider_reports_insider Articles
Insider Reports RSS Feed
|
|