Patch Tuesday: Microsoft pushes nine fixes for 16 flaws
The patches righted 16 flaws in Windows, Internet Explorer, Office, SharePoint, and Visual Basic for Applications.
Yunsun Wee of Microsoft Trustworthy Computing recommended organizations prioritize patching the three critical updates first, which includes a fix for the zero-day vulnerability in Microsoft Core XML Services (MSXML) that was disclosed in early June. Attackers have been targeting the vulnerability already, and exploit code has been added to the BlackHole malware toolkit and to the Metasploit penetration testing framework.
"[Bulletin] MS12-046 has the fix that IT folks have been waiting a month for," Marc Maiffret, CTO of identity management company BeyondTrust, told SCMagazine.com.
However, the update applies to only MSXML versions 3, 4, and 6. The fix for MSXML 5 is expected at a later date as the Microsoft team has not yet finished testing the patch, so organizations running Office 2003 and 2007, Office Word Viewer, Expression Web Edition, Office SharePoint Server 2007, and Groove Server 2007 are left unprotected, Maiffret said.
However, since MSXML 5 is not on the pre-approved ActiveX controls list, users should see a big warning when browsing to a site that tries to load the MSXML 5 ActiveX control, so they would notice when they are being targeted, he said.
Microsoft issued a Fix-It document shortly after disclosing the flaw, which outlined some mitigation activities organizations can apply while waiting for the patch. Organizations with version 5 should implement the Fix-It if they haven't already done so, Maiffret said.
Meanwhile, the cumulative update for Internet Explorer 9 addresses two critical vulnerabilities and should be applied immediately.
"Both can be triggered through a malicious web page, and both allow the attacker remote code execution, [meaning] full control of the targeted machine," said Wolfgang Kandek, CTO of vulnerability management firm Qualys. Microsoft assigned an Exploitability Index rating of 1 to these bugs, which means the company believes attackers would be able to easily reverse engineer the patch and develop an exploit within 30 days.
The third critical bulletin is an update for the Microsoft Data Access Component (MDAC) in Microsoft Windows. The most likely attack vector is through the web browser, Kaspersky Lab's Kurt Baumgartner said. This flaw is "reminiscent" of an older MDAC vulnerability which was added to several popular exploit toolkits and is still seen in attacks, Baumgartner said.
Maiffret agreed. "This new MDAC vulnerability looks to be something that also will make its way into exploit toolkits sooner than later given it affects most OSs and is a straight forward to exploit."
Along with the patches, Microsoft also issued two security advisories. The first described changes in how the software giant will handle certificates and the upcoming certificate management tool for recent versions of Windows. RSA certificates with fewer than a 1,024-bit key length will be considered insecure by default, according to the advisory. The new certificate management tool will allow Microsoft to react more rapidly to certificate problems, such as the one that enabled the Flame virus to spread.
The second advisory offers users a tool to disable "Gadgets" in Windows Vista and 7 as support is being discontinued by Microsoft. Gadgets will not exist in Windows 8.