After a record-breaking December release, Microsoft on Tuesday issued two security bulletins that address three vulnerabilities. Microsoft only rated one of the vulnerabilities critical.
“The critical Microsoft Data Access Components vulnerability is one of two MDAC issues fixed this month,” said Joshua Talbot, security intelligence manager for Symantec Security Response. “These components are a collection of technologies that enable applications — both from Microsoft and third-party developers — to access and manipulate databases. The patch for the critical vulnerability corrects a problem in the way MDAC validates memory allocation.”
The other patch fixes an issue — marked as important — in the way MDAC validates third-party usage of a Microsoft API. Talbot said both vulnerabilities can be exploited by drive-by download, meaning simply viewing a legitimate site that has been compromised by an attacker can lead to a user’s machine being exploited.
DLL Pre-Loading Attacks
There’s also a vulnerability in the Windows Backup Tool that is rated important and only applies to Windows Vista. While DLL pre-loading is an old system issue in Windows and many other operating systems, it gained new attention last August when many vulnerable applications were identified, said Wolfgang Kandek, CTO at Qualys.
“Secunia maintains a list of Microsoft and third-party applications that have been shown vulnerable to the DLL pre-loading attacks. The list has over 200 vulnerable programs and includes the Vista Backup vulnerability that is being fixed today,” Kandek said. “Given the scope of the DLL pre-loading vulnerabilities, we highly recommend implementing the work-around that Microsoft describes in Security Advisory 2269637, which neutralizes the most common attack vectors on the operating-system level.”
The Unpatched Holes
Andrew Storms, director of security operations at nCircle, said instead of talking about the number of bulletins that were patched on Tuesday, everyone’s mind is on the five vulnerabilities that aren’t being patched.
“Microsoft always…