This month Microsoft issued 11 bulletins that address a record 26 vulnerabilities, 17 of them rated as critical. The 26 vulnerabilities are the most Microsoft has addressed since it had 25 in August 2006, which also had 17 rated as critical.
The patch for the vulnerability in the Snapshot Viewer for Microsoft Access ActiveX control is important because shortly after the issue became public on July 7 there was evidence of it actively being exploited, according to Ben Greenbaum, senior research manager for Symantec security response.
“Since then, attackers have fine-tuned their exploits, resulting in even more widespread attacks,” Greenbaum said. “The Snapshot Viewer issue impacts any Internet Explorer 7 users that have the ActiveX control installed and any Internet Explorer 6 users regardless if they have the control installed or not. The nature of the control allows the attacker to install [malicious code] and exploit the vulnerability without any user interaction.”
An Early End to Summer Vacation
Summer vacation may be over a little early for network security professionals. All seven critical patches are identified as fixing “remote code execution” vulnerabilities that can in many cases give criminals control of a computer and access to its resources.
To make things even busier, IT teams need to ensure that they have addressed two recent and important Microsoft Security Advisories, said Don Leatham, director of solutions and strategy at Lumension Security. Those advisories are MS-954960 and MS-956187.
“Once exploit code for the DNS vulnerability announced in July became available, Microsoft took the unusual step to issue this security advisory that encouraged customers to update their DNS servers ASAP, even though the original bulletin rating was an Important and not as Critical,” Leatham said. “Given the publicly available exploit code and the possible compromise of critical DNS services, IT teams that have not deployed this…