Showing posts with label patch. Show all posts
Showing posts with label patch. Show all posts

Sunday, 22 September 2013

Patch Monday: A way to avoid more Microsoft Automatic Update fiascos

Patch Monday: A way to avoid more Microsoft Automatic Update fiascosn

This month's Black Tuesday -- Sept. 10, 2013 -- enters the record books as Microsoft's most patch-botching month in history. That's quite an accomplishment, frankly. Having followed Microsoft's bungled patch efforts since long before the ascendancy of Patch Tuesday, I think there's a better -- if rather unorthodox -- way to manage patching.

The release dilemma is quite straightforward: Microsoft has to test the patches without letting them leak to the bad guys. Conventional wisdom dictates that if the bad guys can reverse engineer the patches before they roll down the Automatic Update chute, Windows as we know it will cease to exist. However, given the recent revelations of governmental stockpiling of zero-days, the ascendancy of companies that specialize in selling such zero-days to governments and corporate spies alike, and the fascinating proposal that the U.S. government share its zero-day trove with private companies (for a fee, of course), I think the day-and-date exposure threat is way overblown.

Here's my proposal: Instead of rolling all the patches out via Automatic Update on Black Tuesday, engulfing an unsuspecting public and creating all sorts of buggy havoc, I think Microsoft should let volunteers test the patches one day earlier. Call it Patch Monday. That would give software manufacturers, corporate customers with patch testing capabilities, enthusiasts and, yes, hackers, a one-day head start on the pandemonium that invariably ensues upon unleashing Automatic Updates.

Microsoft would put together all of the patches as it now does for Black Tuesday. But instead of keeping the security patches under wraps until the fateful moment on Tuesday when millions and millions of machines get hit almost simultaneously, it should let volunteers take a swing at them 24 hours earlier.

That would've given Kaspersky Antivirus, for example, a chance to test KB 2823324 a day before its release and to discover that older versions of Kaspersky would freeze. It would've given ambitious Outlook 2013 users a chance to see before KB 2817630 hit that their folders disappeared. It would've offered Office Starter Edition users a chance before KB 2589275 got rammed down the Automatic Update chute to scream about the fact that they're being told to buy Office 2010. The Brazilian manufacturer of the banking security plugin "G-Buster" might've avoided the massive meltdown of PCs in Brazil after KB 2823324 hit. And on and on.

Of course, the immediate argument is that, by opening up an all-volunteer Patch Monday, you're giving the bad guys a head start -- an extra day to reverse-engineer the patches and wipe out the Internet. To which I say, "baloney," or something less printable.

The really bad guys already have hundreds of zero days at their disposal. Chances are very good that the most tied-in government-sponsored crackers already know about the holes that Microsoft is going to patch. The real vulnerability lies with bad guys who aren't working for the government. They  don't have enough money to buy a zero day, but they're capable of reverse engineering and distributing a massive malicious attack in 24 hours. Yes, such people do exist.

Microsoft already has a rating system that can pinpoint patches vulnerable to those kinds of attackers. Every security bulletin these days has three key components, described in a TechNet article, which you can see readily on the SANS Internet Storm Center listing for each Black Tuesday. Each security bulletin (and presumably each individual patch) gets rated with a severity level, an exploitability level, and a description of whether the hole has already been publicly disclosed.

My proposal for Patch Monday has some wiggle room for Microsoft: If a particular patch (not a security bulletin, but an individual patch) has a severity rating of critical, an exploitability rating of 1, and it has not yet been publicly disclosed, Microsoft may (that's the operative word) choose to withhold the patch from Patch Monday volunteer testing.


View the original article here

Wednesday, 11 September 2013

Microsoft Patch Tuesday brings critical Explorer, Outlook fixes

Microsoft has shipped fixes for critical vulnerabilities in Internet Explorer and Outlook as part of September's round of vulnerability fixes.

Overall this month, Microsoft issued 13 bulletins -- 4 for them critical -- that cover 47 vulnerabilities found across Internet Explorer, Outlook, SharePoint, Office and the Windows kernel. It is an exceptionally large number of patches for any one month, said Wolfgang Kandek, CTO of IT security firm Qualys.

[ Security expert Roger A. Grimes offers a guided tour of the latest threats and explains what you can do to stop them in "Fight Today's Malware," InfoWorld's Shop Talk video. | Keep up with key security issues with InfoWorld's Security Adviser blog and Security Central newsletter. ]

Of this round of patches, enterprise security professionals should take a look first at MS13-068, which details a vulnerability allowing for remote code execution in Microsoft Outlook, Kandek said.

This remote code execution vulnerability is particularly dangerous because it does not require user interaction to launch.

The flaw lies in how Outlook handles incoming user certificates, which identify the sender of an email. Outlook's certificate parser can recognize only 256 certificates in any one email.

"The programmer [probably] said 'Well, no one would nest more than 256 certificates,' and no one in their right mind would," Kandek said. "But an attacker would. They always go after this sort of thing."

A hacker could nest more than 256 certificates in an email, which would cause a buffer overflow that could place malicious data in the computer's memory. Microsoft failed to add a mechanism that would check to ensure no more than 256 certificates have been submitted to the parser by any single email.

An exploit for this vulnerability would not require the user to click on anything. Code could automatically be triggered simply by displaying the contents of the email message in a preview window.

MS13-069 for Internet Explorer, a collection of 10 patches, should be dealt with as soon as possible as well, Kandek advised. With these vulnerabilities, an attacker could plant malicious code on a Web page that, when visited by an unpatched browser, could take control of the user's machine, said Amol Sarwate, director of Qualys' Vulnerability Labs .

While Microsoft rated bulletins for Microsoft Office Word, MS13-072, and Excel, MS13-073, as important -- rather than critical -- they still could be harmful to the enterprise if not applied, Kandek said.

Both of these bulletins focus on file format vulnerabilities. They require a user to open a file in order to initiate code that would take control of the computer. Kandek pointed out that environments with sensitive data could be subject to spear-fishing attacks that use these vulnerabilities, in which an attacker may devise a way to fool the user into opening a malicious file.

In addition to the Microsoft patches, administrators should also take a look at the critical patches that Adobe also issued Tuesday for Reader and Flash. Users of Google Chrome and Internet Explorer will have the Flash patches applied automatically, Kandek said.

Joab Jackson covers enterprise software and general technology breaking news for The IDG News Service. Follow Joab on Twitter at @Joab_Jackson. Joab's e-mail address is Joab_Jackson@idg.com


View the original article here

Sunday, 8 September 2013

Microsoft to patch dangerous Outlook hack-by-preview bug next week

Microsoft today said it will ship 14 security updates next week to patch critical vulnerabilities in Internet Explorer (IE), Windows, Office, and SharePoint, its enterprise collaboration platform.

The IE update, slated to affect every supported version, from the soon-to-be-retired IE6 to the newest IE10, was at the top of most security experts' lists, including the one crafted by Andrew Storms, director of DevOps at CloudPassage.

[ Security expert Roger A. Grimes offers a guided tour of the latest threats and explains what you can do to stop them in "Fight Today's Malware," InfoWorld's Shop Talk video. | Keep up with key security issues with InfoWorld's Security Adviser blog and Security Central newsletter. ]

Microsoft has patched IE every month so far this year, Storms said, the fruit of a change in July 2012, when Microsoft ditched a years-long practice of updating the browser on alternate months. The company patched IE in June, July, August and September 2012 to demonstrate its new capabilities before pausing, then returned to IE last November and December.

"I expect we'll see IE updates every month from now on," said Storms, basing his take on the 11-months-straight stretch. That would put Microsoft's patch tempo between that of its chief browser rivals, Google and Mozilla, which update their Chrome and Firefox applications several times monthly or once every six weeks, respectively.

Of the 14 updates slated to ship next Tuesday, Microsoft pegged four as critical, the company's most severe rating. The other 10 will be labeled "important," the next step down in Microsoft's four-step threat system.

Storms also put the spotlight on what Microsoft marked as "Bulletin 2," which will quash one or more bugs in Outlook 2007 and Outlook 2010, the email clients included with Office 2007 and Office 2010, the most widely-used editions of the company's productivity suite.

While Microsoft kept to its practice of not disclosing details of the underlying vulnerabilities in its Thursday notification, another researcher predicted that the Outlook flaw would turn out to be extremely dangerous.

"Past patterns in critical Office vulnerabilities have always been through the preview pane," said Wolfgang Kandek, CTO of Qualys, in an email. "It is pretty much the only way to get into Outlook without user interaction, which is Microsoft's criteria for a critical rating."

Kandek argued that the bug or bugs to be patched by Bulletin 2 will turn out to be exploitable if hackers can simply get users to preview an e-mail in Outlook.

Such vulnerabilities are considered nearly as treacherous as a drive-by browser exploit, said Storms, because by default Outlook automatically displays the contents of each message. He suggested users disable the preview pane in Outlook 2007 and 2010 until more is known of Bulletin 2's vulnerabilities.

"The Outlook update is almost as important as the one for IE, because next to the browser, your email reader is just as popular and important," said Storms of corporate users.

One of the two remaining critical bulletins will affect only Windows XP and Windows Server 2003, while the second will address one or more flaws in SharePoint Server 2007, 2010 and 2013, and in Office Web Apps 2010.

Both were notable to Storms.


View the original article here