Microsoft patches for GDI, DNS vulnerabilities

Microsoft on Tuesday pushed out three patches -- one deemed "critical" -- to resolve eight vulnerabilities.

The critical bulletin addresses three flaws in the Windows kernel, the core of the operating system, including one that affects its Graphics Device Interface (GDI). If users are duped into visiting a malicious website hosting the exploit, they can be infected, said Andrew Storms, director of security operations at vulnerability management firm nCircle.

Storms added that because Microsoft has issued fixes for similar GDI issues in the past, many malware writers will be ready to pounce on the new flaw.

"There are a number of known exploit codes that might be able to be altered for these new bugs," he told SCMagazineUS.com on Tuesday. "A lot of eyeballs are going to go after that."

Security experts said the other major patch that administrators should pay attention to is a fix for four vulnerabilities in the Windows DNS and WINS (Windows Internet Naming Service) servers. Storms said successful exploitation could allow an attacker to poison a target's DNS cache -- although it would take some work.

"Someone on the network would have to guess the transaction ID [associated with individual DNS requests]," he said.

Microsoft graded this fix "important," saying it corrects flaws that could be exploited to permit spoofing attacks. But Eric Schultze, CTO of patch management software provider Shavlik Technologies, said he considers the patch critical.

"The DNS server's sole purpose is to hand out information about what websites were located where," he told SCMagazineUS.com. "This particular vulnerability allows an unauthenticated attacker to remotely modify all that data."

Tuesday's security update also includes a third patch to remedy a single vulnerability in SChannel, a Microsoft authentication protocol suite. The software giant labeled that fix "important."

Missing from the bundle was a fix for a zero-day Excel vulnerability, which has resulted in active attacks. That bug was announced in late February.

Sign up to our newsletters

More in News

Bitcoin mining botnet has become one of the most prevalent cyber threats

Fortinet researchers have tracked 100,000 new ZeroAccess trojan infections per week, making the botnet very lucrative to its owners.

House Intelligence Committee OKs amended version of controversial CISPA

House Intelligence Committee OKs amended version of controversial ...

Despite the 18-to-2 vote in favor of the bill proposal, privacy advocates likely will not be satisfied, considering two key amendments reportedly were shot down.

Judge rules hospital can ask ISP for help in ID'ing alleged hackers

Judge rules hospital can ask ISP for help ...

The case stems from two incidents where at least one individual is accused of accessing the hospital's network to spread "defamatory" messages to employees.