Another Patch Tuesday, another batch of fixes for critical issues. In December’s cycle, Microsoft issued six security bulletins that address 12 vulnerabilities, seven rated as critical. Five of those critical updates fix issues in Internet Explorer that could be used in drive-by attacks.
“Proof-of-concept exploit code was released for the object memory corruption vulnerability late last month, but it wasn’t reliable,” said Ben Greenbaum, senior research manager for Symantec Security Response. “It’s been a race since between Microsoft and attackers to either get a patch out or improve the exploit’s reliability. As it turns out, Symantec has yet to see either the exploit’s consistency increased significantly nor any successful attacks using it in the wild.”
Microsoft Under Scrutiny
Any improvement in browsing security is a nice holiday gift to consumers surfing through their inboxes every morning for the best holiday shopping deals, said Andrew Storms, director of security operations for nCircle. However, he added, Microsoft’s secure-code development practices are going to come under scrutiny again because the IE update includes fixes for two previously nonpublic exploits that only affect IE8, the newest browser from Microsoft.
“There’s no way for Microsoft to avoid the speculation that these bugs should have been found during the software development and quality assurance cycle, but the reality is that this was bound to happen,” Storms said. “Every product has bugs, and more features means greater attack surfaces. It is depressing for both Microsoft and its customers, though, that it happened so quickly.”
Beyond the IE Flaws
Beyond IE, December’s Patch Tuesday list is really a mashup of random fixes, said Tyler Reguly, senior security engineer at nCircle. There’s a lot of letters with LSASS, ADFS and IAS and a smattering of client-side vulnerabilities, but in the grand scheme of things, he said, there’s nothing extremely dangerous once…