Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Microsoft Patches Duqu Vulnerability as Part of 13 Security Bulletins

As part of their scheduled patch cycles, Microsoft and Adobe Systems today released patches aimed at securing users.

Microsoft released 13 security bulletins today for Patch Tuesday, including a patch for the security vulnerability (MS11-087) exploited by Duqu. Adobe meanwhile issued an update for its ColdFusion software for Windows, Mac and UNIX that closes a pair of cross-site scripting vulnerabilities in version 9.0.1 and earlier.

As part of their scheduled patch cycles, Microsoft and Adobe Systems today released patches aimed at securing users.

Microsoft released 13 security bulletins today for Patch Tuesday, including a patch for the security vulnerability (MS11-087) exploited by Duqu. Adobe meanwhile issued an update for its ColdFusion software for Windows, Mac and UNIX that closes a pair of cross-site scripting vulnerabilities in version 9.0.1 and earlier.

The Adobe vulnerabilities are not currently being exploited in the wild, and Adobe said it is still working on an update for Adobe Reader and Acrobat for Windows to cover the zero-day bug reported to be under attack last week.

As for the Microsoft bulletins, three of the 13 are rated ‘critical’, while the remaining 10 hold the rating of ‘important.’ All totaled, the bulletins close 19 security holes. Among them is a remote code execution bug exploited in the Duqu attacks. The bug lies in the Windows kernel, and exists due to the improper handling of a specially-crafted TrueType font file. Despite the publicity surrounding Duqu however, that particular vulnerability may not be the most dangerous, argued Andrew Storms, director of security operations at nCircle.

“The only truly critical bug is a Windows Media drive-by flaw that should be patched immediately,” Storms said. “The other critical bulletin is a fix for the vulnerability used by Duqu. After many dire predictions in the press, Duqu hasn’t turned out to be much of a threat.”

According to Microsoft, the Windows Media vulnerability Storms is referring to also impacts Windows Media Center and can enable an attacker to execute code remotely if a user is tricked into opening a malicious Microsoft Digital Video Recorder (.dvr-ms) file. The remaining critical bulletin is an update of ActiveX Kill Bits and addresses a remote code execution issues that can be exploited if a user views a specially-crafted Web page that uses a specific binary behavior in Internet Explorer (IE).

Left off of this month’s round of Microsoft patches is a fix for the vulnerability exploited by the BEAST attack tool developed by security researchers Juliano Rizzo and Thai Duong. Angela Gunn, security response communications manager for Microsoft’s Trustworthy Computing Group, explained that the bulletin was dropped from the release because an application-compatibility issue with a “major third-party vendor.”

Advertisement. Scroll to continue reading.

“We’re currently working with that vendor to address the issue on their platform, after which we’ll issue the bulletin as appropriate,” she blogged. “As ever, we’d much rather withdraw a potential bulletin than ship something that might inconvenience customers, however limited that inconvenience in scope.”

Written By

Click to comment

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

SecurityWeek’s Threat Detection and Incident Response Summit brings together security practitioners from around the world to share war stories on breaches, APT attacks and threat intelligence.

Register

Securityweek’s CISO Forum will address issues and challenges that are top of mind for today’s security leaders and what the future looks like as chief defenders of the enterprise.

Register

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Vulnerabilities

The latest Chrome update brings patches for eight vulnerabilities, including seven reported by external researchers.

Vulnerabilities

Patch Tuesday: Microsoft warns vulnerability (CVE-2023-23397) could lead to exploitation before an email is viewed in the Preview Pane.

Vulnerabilities

Apple has released updates for macOS, iOS and Safari and they all include a WebKit patch for a zero-day vulnerability tracked as CVE-2023-23529.

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

IoT Security

A vulnerability affecting Dahua cameras and video recorders can be exploited by threat actors to modify a device’s system time.