Virtual Event Today: Ransomware Resilience & Recovery Summit - Login to Live Event
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Management & Strategy

Patch Tuesday: Microsoft Releases 13 Security Bulletins, Some Critical

Microsoft released 13 security bulletins today as part of Patch Tuesday, including two rated “critical” – its highest security rating. But according to some security pros, companies would be wise to not give some of the non-critical bulletins short-thrift when it’s time to prioritize patches.

Microsoft Logo

Microsoft released 13 security bulletins today as part of Patch Tuesday, including two rated “critical” – its highest security rating. But according to some security pros, companies would be wise to not give some of the non-critical bulletins short-thrift when it’s time to prioritize patches.

Microsoft Logo

Though Microsoft only gave the bulletins for Internet Explorer (MS11-057) and Windows DNS Server (MS11-058) a critical rating, researchers at nCircle warned there are other vulnerabilities that enterprises need to pay attention to as well. While he agreed the IE bulletin should be a top priority, Tyler Reguly, nCircle’s technical manager of security research and development, added the DNS server issue may not be as important as some others due to the relative unlikelihood of exploitation.

“Microsoft listed the DNS server vulnerability as ‘critical’ and placed it above other issues, such as cross site scripting and the remote ‘blue screen of death’,” he said. “Given the exploitability index assigned to this vulnerability, and the importance of XSS as an attack vector, I’m not sure I fully agree.”

Andrew Storms, director of security, at nCircle, added that MS11-064 – which patches two bugs that could be exploited to launch denial-of-service attacks – demands special attention as well.

“Attackers can take advantage of this bug to cause a remote reboot of Windows computers even if they have a local firewall enabled,” he said. “Back in the early 90’s, we used to call this kind of bug the ‘ping of death.’ It will take about 10 minutes for attackers to write and distribute an attack tool to take advantage of this bug. Then, anyone can easily grab that attack tool and, with a single click, cause your Windows network to reboot. The malicious potential is enormous.”

“The most troubling thing about this bug is that the local Windows firewall does not mitigate the attack,” he said. “Service providers like ISPs, cloud providers and others that allow in-bound ping packets to their server instances should immediately look for ways to mitigate this bug using edge firewalls.”

In both the Internet Explorer and Windows DNS Server updates, the most serious of the bugs being patched can be used by attackers to remotely execute code. In the case of MS11-057, the most severe vulnerability can be exploited by tricking a user into viewing a specially-crafted Webpage using Internet Explorer, the company warned.

In MS11-058, the most serious bug permits an attacker to remotely execute code if the attacker sends a malicious Naming Authority Pointer (NAPTR) query to a DNS server. Servers that do not have the DNS role enabled are not at risk of attack, Microsoft said.

Advertisement. Scroll to continue reading.

According to Microsoft, there are no attacks targeting any of the issues addressed in MS11-057 and MS11-058 as of now. Of the remaining bulletins, nine are rated “Important”, while the other two are considered “Moderate.” All totaled, the 13 bulletins cover 22 vulnerabilities across Microsoft’s product line.

“Overall this Patch Tuesday is on the large side,” said Dave Marcus, director of security research and communications at McAfee Labs. “Although there are only two critical patches this month, this update comes after the July patches from Oracle and Apple, and there will be another release of critical patches for Adobe Flash Player today, leaving IT administrators with a full plate this summer.”

Written By

Marketing professional with a background in journalism and a focus on IT security.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

Professional services company Slalom has appointed Christopher Burger as its first CISO.

Allied Universal announced that Deanna Steele has joined the company as CIO for North America.

More People On The Move

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

CISO Strategy

SecurityWeek spoke with more than 300 cybersecurity experts to see what is bubbling beneath the surface, and examine how those evolving threats will present...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

CISO Conversations

Joanna Burkey, CISO at HP, and Kevin Cross, CISO at Dell, discuss how the role of a CISO is different for a multinational corporation...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...