Patch Tuesday: Time to use the Flame-retardant Windows Update client

By , Network World |  Security, Microsoft

When Patch Tuesday rolls around next week, Microsoft will address three critical security issues using an improved version of Windows Update that closes a loophole exploited by Flame malware.

That update to Windows Update has been distributed by Microsoft since the middle of last month but missed June's Patch Tuesday. The fix is important because it addresses the flaw that allowed Flame's authors to certify that malware they were sending to victim machines was authenticated by Microsoft, making the malware as trusted as an actual Windows security update.

MORE: Price tag for Microsoft piece of Flame malware $1M, researcher says

NEWS: Federal appeal court raps bank over shoddy online security

As for the July security bulletin being released next Tuesday, Microsoft says it is issuing nine security bulletins, three of them critical and designed to shore up vulnerabilities in Windows. One of them also affects Internet Explorer.

Each of the critical bulletins address flaws that if exploited could result in remote code execution on attacked machines. The browser vulnerability affects Internet Explorer 9, the latest version of the software.

Other platforms affected by the three critical updates are certain versions of Windows XP; Windows Server 2003, 2008 and 2008 R2; and Windows 7.

While Microsoft policy is not to reveal ahead of time what vulnerabilities are being addressed in its security bulletins, security experts have some idea what may be included.

"Bulletin 1, rated 'critical,' affects all versions of Windows, and we expect it to address the XML vulnerability disclosed by Microsoft in June's Patch Tuesday as KB2719615," says Wolfgang Kandek, CTO of Qualys Inc., in a blog. "This bulletin will be the highest priority for users, at least for those who did not apply Microsoft's FixIt supplied in the advisory."

Originally published on Network World |  Click here to read the original story.
Join us:






Spotlight on ...
Online Training

    Upgrade your skills and earn higher pay

    Readers to share their best tips for maximizing training dollars and getting the most out self-directed learning. Here’s what they said.


    Learn more

Answers - Powered by ITworld

ITworld Answers helps you solve problems and share expertise. Ask a question or take a crack at answering the new questions below.

Ask a Question