Change Language
Sun Sun Sun

You are here: News >> IT Security News >> New Record in Flaw Fixes for Patch Tuesday

» IT Security NEWS
 
» 14 October 2009
New Record in Flaw Fixes for Patch Tuesday

A record number of fixes and patches were released this Patch Tuesday, which includes thirteen bulletins that corrected thirty-four security holes targeting Silverlight, Developer Tools, Forefront, SQL Server, .NET framework, Office, Internet Explorer, and Windows. It was a veritable system overhaul that includes at least one bug that was already being exploited in the wild.

One of the updates corrected a Windows Media Runtime security hole that enables hackers to remotely launch malicious software by duping the user into running a specially crafted bogus video or audio file. More to the point, this security update patches the bugs in GDI+ that allows hackers to remotely execute their malicious code.

Several hours after the GDI+ fix's release, a company representative claimed that Microsoft's researchers have seen few attacks that actually took advantage of the vulnerability. Nevertheless, this is still a critically rated glitch on every Windows version available. Moreover, users who are utilizing administrative user rights will probably be more affected by the issue than those whose accounts are configured to have fewer user rights.

In addition, the security update resolves the bugs found in FTP features for Internet Information Services that also enables hackers the option for remote code execution. The vulnerabilities in the FTP feature in Microsoft Internet Information Services (IIS) 7.0, Microsoft IIS 6.0, Microsoft IIS 5.1, and Microsoft IIS 5.0 had previously been disclosed and addressed publicly as well.

Furthermore, there was also an update that fixed a notorious vulnerability that left browsers such as Apple Safari, Google Chrome, and Internet Explorer exposed to fake SSL (secure sockets layer) certificates. The bug that was found in Microsoft's CryptoAPI was exposed ten weeks ago, but patching it soon became a top priority after a cyber terrorist used the research of Moxie Marlinspike (a renowned white-hat hacker) to develop a forged PayPal certificate that made it ridiculously easy for anyone to begin a man-in-the-middle attack to impersonate the Internet payment site.

The patches also had an SMB2 file-sharing fix that aids the services added to Vista and later versions of Windows (particularly Windows 7). About a month ago, white-hat hackers created a dependable method of targeting the critical security hole despite the fact that there have been no reports of it being exploited in the wild so far.

 

24 Hour Open Web Shop

Got a Question? - Call us!
EU: +45-70-235-245
US Toll Free: +1-888-704-7297
Sent us an Email!

Get a Free Vulnerability Scan

Get a Free SEO Blackhat Scan


  Email :
     
SecPoint News
 
02 September 2010
New Penetrator Firmware 7.7.6 ...
31 August 2010
IBM corrects security report a...
30 August 2010
QuickTime found to be vulnerab...
View More...
 
Customer References
 
View More...
   
Product Awards
 
View More...
Privacy Statement | Link Policy | User Policy | IT Security Blog | IT Security Forum | SecPoint Pictures
Event Pictures | Exploit Archive | IT Security Web Shop | Vulnerability Library
IT Security Video | Sitemap
© Copyright 1999-2010: SecPoint®
SecPoint ApS - Lergravsvej 53 - 2300 Copenhagen S - Phone +45 70 235 245
Recent awards Compatible with Visit us on Facebook! Visit us on LinkedIn! Visit us on Myspace!
   
Facebook
Group!


Follow us on Twitter!
Anti-Spam Appliance - Anti-Spam Firewall - Unified Threat Management Appliance Anti-Virus - Web Filter Appliance - Anti Spam Appliance - Anti Spam Firewall - UTM Appliance Wifi Security - Wifi Pen Test - Wifi Crack - Wifi Hack - Wifi Audit - Wep Wpa2 Crack Vulnerability Scanner - Vulnerability Assessment - Security Scanner - Pen Test Appliance