Microsoft released 10 security bulletins to address 34 individual vulnerabilities in June’s Patch Tuesday. The patches include fixes for critical flaws in DirectShow and Internet Explorer. Seven patches are rated important.
“The impact will be felt enterprise-wide, as the bulletins cover a large portion of Microsoft’s range of operating systems, infrastructure products, and Office products, so it is strongly suggested that IT administrators investigate and prioritize this patch load as soon as possible,” said Don Leatham, director of solutions & strategy at Lumension.
Focus on IE
MS10-033 addresses two vulnerabilities in Windows that could lead to remote code execution. This bulletin affects Windows Media, which is very common with popular social-media networking applications. Opening a specially crafted media file or connecting to a malicious server streaming media content can lead to remote code execution.
“The days of solely focusing on Internet browsers for patching have changed and Microsoft is very focused on fixing vulnerabilities in their media formats and players. As we move toward a media-centric audience, attackers are focusing more and more on media players to go along with browser attacks,” said Jason Miller, data and security team manager at Shavlik Technologies.
“I can guarantee that someone on your network, right now, is browsing the Internet looking for a video with Tom Cruise’s Tropic Thunder character Les Grossman’s dance routine from the MTV Movie Awards, and there’s a good chance one of those video files has been compromised,” Miller said.
But there is good news, according to Andrew Storms, director of security operations at nCircle. Critical bugs are still being found in IE8 and Windows 7, but they are harder to exploit because of Microsoft’s mitigation technologies. “The underlying bugs are still there,” he said, “but IE protected mode, Windows DEP and ASLR make them far less attractive to…