Microsoft fixes critical Web bugs with security updates

By Robert McMillan, IDG News Service |  Windows, Microsoft, patch 1 comment

Microsoft released two security updates for its Windows operating system Tuesday to patch flaws that could give attackers new ways to install malicious software on a victim's computer.

The MS08-069 update fixes critical flaws in the Microsoft XML Core Services used by Internet Explorer and other programs to render Web pages. The second MS08-068 update fixes a less-critical bug in the Windows Server Message Block (SMB) software used by Windows to share files and print documents over a network.

Hackers routinely use Web bugs such as these XML flaws to infect Windows machines. "Anytime Microsoft updates Web vulnerabilities they're going to rate them as critical," said Andrew Storms, director of security operations with security vendor nCircle. For a Web-based attack to work, the victim must first visit a compromised Web page or open an e-mail that displays the malicious code.

Microsoft rates the SMB update as "important" for Windows XP, 2000 and Server 2003 users, and only "moderate" on Vista and Server 2008. But enterprise users should still take it very seriously, said Eric Schultze, chief technology officer at Shavlik Technologies.

While a firewall would block an SMB attack from the Internet, someone who controlled a machine within the corporate network could exploit this flaw to get access to another computer in what's known as an SMB relay attack. "I would label this as critical on a corporate network," he said.

To make matters worse, the SMB flaw was already publicly disclosed prior to Tuesday's updates, Microsoft said.

With just two updates, this is one of the quieter patch releases Microsoft has had this year. But there was some excitement at the end of October when Microsoft took the unusual step of issuing an emergency patch for a bug in the Windows Server service.

Microsoft had spotted this flaw being used in a small number of targeted attacks, and the bug was considered so serious that Microsoft decided to rush out the early patch ahead of Tuesday's regularly scheduled security updates. This flaw has not been used in widespread attacks, however, security vendors say.

1 comment

    Samuel Kamau
    Samuel Kamau 3 years ago
    It is a good step that Microsoft has taken.

      Add a comment

      Post a comment using one of these accounts
      Or join now
      At least 6 characters

      Note: Comment will appear soon after you have activated your account.
      Obscene/spam comments will be removed and accounts suspended.
      The information you submit is subject to our Privacy Policy and Terms of Service.

      ITworld LIVE

      WindowsWhite Papers & Webcasts

      White Paper

      Microsoft Volume Licensing Reference Guide

      This guide provides an overview of the key features of Microsoft Volume Licensing programs. The information is presented by organizational type and size-two of the most important keys to determining your best Volume Licensing option.

      White Paper

      HP Software Licensing & Management Solutions for Microsoft

      See how HP Software Licensing & Management Solutions (SLMS) can help you identify the best Microsoft licensing program for your needs, get the most from your licensing agreement, and maximize your Microsoft software investment.

      White Paper

      Microsoft Open Value Program Guide

      In this overview, see how Microsoft Open Value provides a flexible, affordable way for small to midsize organizations (i.e. those with five or more desktop PCs) to use and manage all their Microsoft licensed products under a single agreement.

      White Paper

      Microsoft Volume Licensing Comparison - Enterprise

      With this quick-reference document, you can easily compare the available Microsoft Volume Licensing programs for enterprise organizations with 250+ devices, and tailor a program to help save costs, manage multiple licenses, and keep software up-to-date.

      White Paper

      Microsoft Enterprise Agreement Program Brief

      This white paper provides an in-depth look into how the Microsoft Enterprise Agreement Program provides with flexibility to choose among on-premises software and cloud services to best suit your user needs, and helps you optimize your technology spend as business priorities change.

      See more White Papers | Webcasts

      Answers - Powered by ITworld

      Ask a question

      Ask a Question