In a relatively light cycle, Microsoft has issued three security bulletins to address four vulnerabilities. Two bulletins are for Windows and one is for Office. Redmond rated only one critical.
Joshua Talbot, security intelligence manager at Symantec Security Response, said
the lone critical issue this month — the DVR-MS vulnerability — will be somewhat trivial for attackers to exploit.
“It also allows attackers to skip a few of the traditional steps needed to get malicious code to execute on a targeted computer,” Talbot said. “This is because when processing DVR-MS files, Windows Media Player and Media Center use data in these files themselves to determine what code in memory gets executed. This allows an attacker to jump directly to executing malicious code.”
Don’t Take It Too Lightly
Paul Henry, forensic and security analyst at Lumension, warns IT admins not to be fooled by the light patch load. As he sees it, there’s still more than enough work to go around. Despite issuing just three bulletins, the implications are serious. That’s because all the patches aim at issues that allow remote code execution.
Henry said enterprises using the Remote Desktop Client, should make MS11-017 the top priority, followed by MS11-015 and finally MS11-016. Enterprises that are not using Remote Desktop Client but are regularly sending and receiving large media files should focus on MS11-015 first.
“Microsoft may have cleaned up a lot of loose ends with the release of Windows 7 and Windows Server 2008 R2 Service Pack 1 last month, leaving little to address this Patch Tuesday,” Henry noted. “That being said, the patches released today did not address the recently disclosed MHTML issues and we expect a resolution in April’s patch release.”
April Showers?
Andrew Storms, director of Security at nCircle, welcomes what he calls a “lull” in security news from Microsoft, especially considering the…