Microsoft’s October Patch Tuesday list is hauntingly large. Redmond issued 11 bulletins that address 20 vulnerabilities, nine of them rated as critical.
This month’s Path Tuesday also delivered a first — Microsoft’s rankings of how likely it is for a hacker to exploit each vulnerability.
The two critical server-side vulnerabilities in Active Directory and Host Integration Server are of the greatest concern and have the potential to be quite severe, according to Ben Greenbaum, senior research manager for Symantec Security Response.
“Server-side vulnerabilities are still the mechanism of choice for attackers to modify trusted resources, and they are dangerous because they do not require any user interaction and can lead to complete compromise of the host computer,” Greenbaum said. “Once a server is compromised, the attackers typically embed further attacks against that server’s users in public-facing content.”
Rethinking ‘Trusted’ Applications
MS08-56, MS08-57, and MS08-58 are client-side vulnerabilities — and Internet Explorer and Microsoft Office are targets. As the number of client-side vulnerabilities continue to increase, IT admins need to rethink what the average user considers to be a trusted application, according to Tyler Reguly, a security engineer at nCircle.
“If I were to ask my wife, who works in an office, if she had to be concerned about Microsoft Office security when she goes online, she’d most likely ask me why. This is because she thinks of it as an application on the computer,” Reguly said.
Reguly’s point is this: People trust Office because they don’t think about interacting with it online. However, he noted, a Google search could just as easily return a file that takes advantage of Office vulnerabilities as it could IE vulnerabilities. As more of these vulnerabilities are exploited, he continued, it’s critical for people to learn that they can’t trust these traditionally “local” applications.
Meanwhile, vulnerabilities like MS08-061, MS08-064 and MS08-066,…