In a record-breaking Patch Tuesday, Microsoft issued 10 security bulletins and two security advisories this month. The bulletins address a total of 31 vulnerabilities, 17 of which are rated as critical. The previous record was 28 last December. Analysts said enterprises need all hands on deck to get systems patched as quickly as possible.
Of the patches issued this month, the most significant appear to be several that affect Internet Explorer, as the Web continues to be a preferred method of exploit by cybercriminals, according to Ben Greenbaum, senior research manager at Symantec Security Response.
“The four Internet Explorer fixes that address HTML object memory corruption vulnerabilities-the first ever patch for Internet Explorer 8 being among these-are of particular interest,” Greenbaum said. “These weaknesses actually appear to be quite simple to exploit and we have observed malicious code being offered in malware toolkits that have taken advantage of very similar vulnerabilities.”
Is Microsoft Splitting Hairs?
As someone who’s always interested in remote code execution, the MS09-018 bulletin is the most interesting to Tyler Reguly, a senior security engineer at nCircle. He also offered a “notable mention” MS09-022, which fixes the Windows Print Spooler vuln, because malicious servers that exploit the client are always technically interesting.
“I think it’s important to call out the hair splitting that Microsoft seems to be doing these days around the term ‘elevation of privilege.’ MS09-020 allows access to pages requiring authentication when a ‘specially crafted anonymous HTTP request’ is sent,” Reguly said. “Anonymous doesn’t sound like ‘elevation of privilege’ to me, but Microsoft cites the fact that special permissions must be given to the anonymous user as justification.”
Reguly also pointed out that June saw only six out of the 31 vulnerabilities related to listening services. He called this a trend that deserves special attention. If you add in…