internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Songbird

Most Popular Software Downloads
Windows Vista Service Pack 2 (Vista SP2)
Mozilla Firefox 3
QuickTime for Windows
Adobe Flash Player
Windows 7
Norton Internet Security 2010
Internet Explorer 8
CCleaner (Crap Cleaner)
Winamp
Skype

Most Popular Software Articles
Windows Vista Tips: Home Networking Setup Tutorial
10 Must-Have Apps: The Free Windows Networking Toolkit
How to Make Your Internet Connection Faster, Better


Software Reviews

Microsoft Fixes IE in February Patch Update
Security Patches Released for IE, Exchange, SQL Server, and Office
Sean Michael Kerner

Microsoft Internet Explorer IE patches Microsoft today released its monthly Patch Tuesday update, targeting eight vulnerabilities spread across Microsoft's Internet Explorer Web browser, Exchange mail server, SQL database server, and Office applications.

At the top of the patch list is Internet Explorer, which is receiving an update rated "Critical" by the company, designed to close a pair of vulnerabilities.

Microsoft identifies the first of the two flaws as an "Uninitialized Memory Corruption Vulnerability." The issue stems from how IE deals with objects that have been deleted. According to the company's advisory, "an attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution."

The second IE issue deals with a memory corruption vulnerability in how the browser handles Cascading Style Sheets, or CSS (define) — a common layout technology on modern Web sites. Microsoft noted in its advisory that certain types of CSS styles, when loaded by IE, could trigger memory corruption. That corruption could, in turn, potentially enable an attacker to execute arbitrary code.

Microsoft's latest IE updates arrive as the company is coming off a recent spate of trouble with the browser, during which IE exploits grew beyond Microsoft's usual Patch Tuesday updates. In December, Microsoft revealed that it evidently missed a few IE updates, which ended up becoming zero-day exploits. Microsoft released an out-of-cycle patch for IE a few weeks later.

The two newest IE issues are specific to IE 7, and do not affect IE 6 or 5, according to Microsoft. Both also have not been targeted in exploits found in the wild — yet.

"Although there is no known exploit code available today, we expect it to be available soon," Paul Zimski, vice president of market strategy for security patch vendor Lumension, told InternetNews.com.

"This update addresses two separate vulnerabilities that are rated a '1' on Microsoft's exploitability index and are noted as 'Consistent' — exploit code can be crafted easily," he added, referring to Microsoft's recently unveiled, three-level ranking of vulnerabilities' potential danger.

According to Microsoft, exploits that rank "2" or "3" on the index, respectively, are likely to result in "Inconsistent" results, or aren't likely to function at all.

SQL Server and Exchange

Microsoft's latest monthly roundup of updates also deals with Exchange Server, which gets two Critical fixes. One of the fixes deals with a remote code execution vulnerability that could be triggered by a malicious e-mail attachment in Microsoft's Transport-Neutral Encapsulation Format (TNEF) format.

If the vulnerability were to be exploited, an attacker could do whatever they wanted to the database, including changing or deleting data. The update addresses the problem by validating input parameters passed to the procedure, according to Microsoft.

The second issue is triggered by a malicious Messaging Application Programming Interface, or MAPI (define), command that could lead to a denial-of-service attack on a vulnerable Exchange server.

SQL Server also gets a fix — rated "Important" — in the February update, addressing an issue that could potentially lead to unintended remote code execution. The company's advisory on the issue pointed the finger at a parameter checking problem with the "sp_replwritetovarbin" extended stored procedure.

In addition to the application fixes, Microsoft is updating its Malicious Software Removal Tool (MSRT) to identify and remove Win32/Srizbi — the malware responsible for taking over PCs and using them in the widespread Srizbi botnet.

"Historically, Win32/Srizbi has been accused of being responsible for a huge chunk of spam e-mail messages sent in the years after its discovery," Microsoft Threat Research and Response blogger Vincent Tiu wrote. "We hope to make a positive impact with the addition of Win32/Srizbi into MSRT."

As it turns out, that update may address a botnet that's now fading from relevance. Recent reports indicate that Srizbi may have petered out after its main host, McColo, was cut off by its ISPs last year.

News courtesy of internetnews.com

February 10, 2009

Download Internet Explorer Now!Download

Download Microsoft Windows Malicious Software Removal Tool Now!Download

View All Microsoft Service & Security Releases

Contents:
1. Security Patches Released for IE, Exchange, SQL Server, and Office


Additional Articles:

  • Microsoft Issues Major Patch Release in Feb. Cycle
  • Mini-Patch Day for Microsoft
  • Full Plate of Microsoft Patches Expected
  • Microsoft Plugs 10 on Patch Tuesday
  • Critical Windows Patch Around the Corner
  • Warily Watching Worm Variants
  • 'Critical' Patch Released For Windows
  • Microsoft Patches Newest 'Dirty Dozen'
  • Zombies Control Half of Windows PCs
  • Six Fixes on Tap from Microsoft
  • An 'Important' Patch Tuesday
  • Patch Tuesday Targets 'Mammoth' Set of Flaws
  • Microsoft Rates Patched Flaws by Exploitability
  • Microsoft Nabs 28 Flaws in Year's Last Patch Haul
  • Patch Tuesday Won't Fix Excel Hole
  • Microsoft Patch Tuesday Shores Up DNS
  • Microsoft Has Eight Patches on Tap For Tuesday
  • Microsoft Patches PowerPoint Zero-Day
  • Six Critical Microsoft Patches Coming Tuesday
  • 'Patch Tuesday' Will Fix ActiveX Zero-Day
  • Microsoft Plays Catch-Up with Biggest Patch Drop


  • internet.commediabistro.comJusttechjobs.comGraphics.com

    Search:

    WebMediaBrands Corporate Info

    Legal Notices, Licensing, Reprints, Permissions, Privacy Policy.
    Advertise | Newsletters | Shopping | E-mail Offers | Freelance Jobs