Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Microsoft Patches Duqu Vulnerability as Part of 13 Security Bulletins

As part of their scheduled patch cycles, Microsoft and Adobe Systems today released patches aimed at securing users.

Microsoft released 13 security bulletins today for Patch Tuesday, including a patch for the security vulnerability (MS11-087) exploited by Duqu. Adobe meanwhile issued an update for its ColdFusion software for Windows, Mac and UNIX that closes a pair of cross-site scripting vulnerabilities in version 9.0.1 and earlier.

As part of their scheduled patch cycles, Microsoft and Adobe Systems today released patches aimed at securing users.

Microsoft released 13 security bulletins today for Patch Tuesday, including a patch for the security vulnerability (MS11-087) exploited by Duqu. Adobe meanwhile issued an update for its ColdFusion software for Windows, Mac and UNIX that closes a pair of cross-site scripting vulnerabilities in version 9.0.1 and earlier.

The Adobe vulnerabilities are not currently being exploited in the wild, and Adobe said it is still working on an update for Adobe Reader and Acrobat for Windows to cover the zero-day bug reported to be under attack last week.

As for the Microsoft bulletins, three of the 13 are rated ‘critical’, while the remaining 10 hold the rating of ‘important.’ All totaled, the bulletins close 19 security holes. Among them is a remote code execution bug exploited in the Duqu attacks. The bug lies in the Windows kernel, and exists due to the improper handling of a specially-crafted TrueType font file. Despite the publicity surrounding Duqu however, that particular vulnerability may not be the most dangerous, argued Andrew Storms, director of security operations at nCircle.

“The only truly critical bug is a Windows Media drive-by flaw that should be patched immediately,” Storms said. “The other critical bulletin is a fix for the vulnerability used by Duqu. After many dire predictions in the press, Duqu hasn’t turned out to be much of a threat.”

According to Microsoft, the Windows Media vulnerability Storms is referring to also impacts Windows Media Center and can enable an attacker to execute code remotely if a user is tricked into opening a malicious Microsoft Digital Video Recorder (.dvr-ms) file. The remaining critical bulletin is an update of ActiveX Kill Bits and addresses a remote code execution issues that can be exploited if a user views a specially-crafted Web page that uses a specific binary behavior in Internet Explorer (IE).

Left off of this month’s round of Microsoft patches is a fix for the vulnerability exploited by the BEAST attack tool developed by security researchers Juliano Rizzo and Thai Duong. Angela Gunn, security response communications manager for Microsoft’s Trustworthy Computing Group, explained that the bulletin was dropped from the release because an application-compatibility issue with a “major third-party vendor.”

“We’re currently working with that vendor to address the issue on their platform, after which we’ll issue the bulletin as appropriate,” she blogged. “As ever, we’d much rather withdraw a potential bulletin than ship something that might inconvenience customers, however limited that inconvenience in scope.”

Advertisement. Scroll to continue reading.
Written By

Marketing professional with a background in journalism and a focus on IT security.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Cody Barrow has been appointed the new CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

More People On The Move

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Vulnerabilities

Patch Tuesday: Microsoft warns vulnerability (CVE-2023-23397) could lead to exploitation before an email is viewed in the Preview Pane.

IoT Security

A vulnerability affecting Dahua cameras and video recorders can be exploited by threat actors to modify a device’s system time.