Microsoft on Tuesday issued 17 security bulletins that address 40 vulnerabilities, eight of them rated as critical. With the release, Microsoft broke several records.
For starters, Joshua Talbot, security intelligence manager at Symantec Security Response, noted that 17 bulletins are the most ever issued in a single month. And with 106 bulletins in 2010, Microsoft has broken the all-time Patch Tuesday annual record. The next closest was 78 in 2006 and 2008. By Symantec’s count, Microsoft far surpassed the number of vulnerabilities patched in a single year with 261. The previous record was 170, set last year.
Finally Fixing Stuxnet
“The most notable patch this month fixes the fourth zero-day vulnerability used by Stuxnet,” Talbot said. “The Task Scheduler issue allows a regular user to schedule a task that will run with elevated privileges, allowing the newly created task full access to the system. This could lead to a complete compromise of the affected computer. Symantec has also seen two additional threats recently begin leveraging this vulnerability.”
Rapid7 security researcher Josh Abraham agrees with Talbot. But in a month where resources are already limited, thanks to the WikiLeaks drama, he pointed to some good news. In addition to addressing a major Internet Explorer issue that has been circulating in the wild for more than a month, only two of the bulletins are rated critical.
“This means that they require much more time and effort before they can be weaponized and added into an exploitation framework like Metasploit,” Abraham said. “ASLR and DEP are two mitigations that Microsoft has added into their newer versions of Windows. They are used to reduce the impact of many vulnerabilities which make remote code execution more difficult; however, it seems that Microsoft hasn’t done much as of late to reduce the number of bulletins coming out of Redmond.”
Holiday Hactivism
Don Leatham,…