Microsoft released its largest-ever batch of security updates Tuesday, fixing 33 vulnerabilities in Windows, Internet Explorer, and other popular software. Eight of the updates are rated critical and five are rated important.
All the critical vulnerabilities are labeled as remote code execution, which would require system restarts and impact a very broad range of Windows platforms and applications, according to Lumension security and forensic analyst Paul Henry. But, he noted, IT administrators should pay attention to two particular security bulletins, as their vulnerabilities are being exploited in the wild: MS09-050 and MS09-053.
MS09-050 is a critical vulnerability that impacts both Vista and Windows 2008 platforms. While only rated as important, Henry said, MS09-053 should be considered a priority for organizations running public-facing FTP servers. He said organizations that use the Internet daily should also pay close attention to the high-priority critical client-side issues that could allow drive-by hacking exploits.
“Because of the large number of issues covered in this month’s patch release, it is important that organizations carefully review the bulletin in its entirety and then carefully plan their patch-management priorities and process based on the impact on their given product utilization and the likelihood of exploitation,” Henry said. “Simply put, the administrative burden of flaw remediation today is clearly beyond that which can be handled without full flaw-remediation process automation.”
Cleaning Up Old Messes
Andrew Storms, director of security operations for nCircle, has a different take. As he sees it, the bug that is likely to have the biggest impact on Microsoft users will be MS09-051, the speech-codec bug that already has limited exploits in the wild. This is a typical file-parsing issue and similar vulnerabilities have allowed attackers to create drive-by attacks that infect unsuspecting video viewers.
“MS09-056 isn’t a critical vulnerability and it doesn’t rate high on the exploitability index, but it does…