Colossal Patch Tuesday addresses 31 Windows, IE8 vulnerabilities

By Scott M. Fulton, III | Published June 9, 2009, 4:59 PM

Just when it appeared Windows and its associated services were looking more stable month after month, Microsoft chose June to tackle a plethora of vulnerabilities including no fewer than 14 that its security engineers believe could be exploitable within the next 30 days.

Microsoft Security Response Center engineers Adrian Stone and Jerry Bryant were audibly panting as they delivered the news to Microsoft customers today. One critical remote code execution vulnerability that's being treated very seriously affects a much older version of the server product, Windows 2000 Server with Service Pack 4 serving as domain controllers, and running Lightweight Directory Access Protocol. "While it's ranked as a '1,' which means we expect it to be easily exploitable over the next 30 days after [the patch] is released," explained Security Program Manager Lead Adrian Stone, "...it was privately disclosed to us. A security researcher worked with MSRC responsibly to make sure that we did address the vulnerability and release it without any knowledge of the vulnerability to date. It's not being actively exploited, nor is there any data publicly available at this time that talks about [it] in in-depth, technical detail."

That's actually phenomenal news in itself, because Microsoft disclosed the existence of the problem last October. The fact that no one took the bait with this one could be partly due to the age of the OS in question; Windows 2000 Server's support lifecycle is due to expire in a mere five weeks.

"Any time you're talking about remote code execution," Stone warned, "and a network vulnerable-by-default scenario, which is the case with LDAP, with this particular vulnerability, this one would be very high...in my priority to go patch this month."

The first cumulative update for Internet Explorer 8 is also part of today's batch of fixes. It includes a patch for a problem that was identified, Stone admitted, during last March's CanSecWest security conference in Vancouver. There, as part of the conference's "Pwn2Own" contest, one security researcher successfully wrested control of a Sony Vaio running a pre-release version of IE8 on a Windows 7 beta.

"It was a very interesting discovery," said Stone today, "...one of the unique opportunities of being able to work with the security community to identify vulnerabilities in our products, especially prior to release and prior to launch. Soon after, we had an update in hand to address the issue." Interestingly, Stone went on to say that the vulnerable code in question is normally not accessible through outside means, due to two technologies introduced with Windows Vista: Address Space Load Randomization (ASLR) and Data Execution Prevention (DEP). For that reason, the vulnerability only rates a more moderate "3" on Microsoft's exploitability index in Vista specifically, while rating a "1" in Windows XP (highest level). While Stone didn't go on to mention this little fact, it was a Windows 7 beta machine that was "pwned" at CanSecWest, and the exploitability index for Win7 is also being rated a "1."

As company security engineer Jonathan Ness explained last March after the Vaio machine went down, "The final release of Internet Explorer 8 on Windows Vista blocks the .NET DEP+ASLR bypass mechanism from malicious Web sites on the Internet. Specifically, IE8 created a new URLAction that regulates loading of the .NET MIME filter. By default, the URLAction prevents it from loading in the Internet and Restricted Sites Zones. The .NET MIME filter is allowed to load by default in the Intranet Zone."

But the mitigation that Ness refers to may not yield the same results in the Windows 7 Release Candidate, for reasons no one has yet explained, although the relative severity of the vulnerability in Win7 is being acknowledged. The cumulative update introduced in this bulletin issued today will address the CanSecWest issue for all current versions of Windows, although the applicability of this update will likely best be felt by users of XP and Win7 RC.

Comments

View comments by with a score of at least

"The fact that no one took the bait with this one could be partly due to the age of the OS in question; Windows 2000 Server's support lifecycle is due to expire in a mere five weeks."

Dangit Scott, please check facts like that before scaring the crap out of me!!! It's on July 13, 2010 (http://support.microsoft.com/lifecycle/?p1=7274) that Server 2000 loses its extended support. Thank God, because we aren't planning to upgrade/replace our 2000 servers until late this year.

Score: 0

|

I don't use Office on my main PC or laptop. No updates so far, 1 Windows Defender update installed.
On my guest PC which does have Office 2007 I got 8 updates. Windows 7 64bit on all machines.

I haven't checked my Vista machine yet (HTPC).

Score: -1

|

8 updates on Windows 7 64-bit with Office 2007 and no reboot required.

Score: 0

|

15 updates for Vista SP2 and Office 2k7 SP2.

Edit - better note that it's the x64 version.

Score: 0

|

Somehow I came up with 15.

Score: 0

|

It looks to me like the IE8 updates, as they relate to Windows 7, are for the Beta only, not the RC. I'm running Release Candidate x64 build 7201 and I didn't get any updates applied at all. Edit: I do not have MS Office installed.

If anyone out there running Windows 7 RC build 7001 can confirm or refute this for that build, let me know.

Score: 1

|

It was 13 in total for me, with one of those being the IE8 website compatibility list.

Also, I thought DEP was in XP?

Score: 0

|

It is, but ASLR isn't. Also, many people will have DEP turned off on XP for compatibility/stability reasons - but I haven't encountered any need to do so on Vista machines.

Score: 0

|

very newsworthy :P i'm patched and updated, seems it was 6 updates for vista... move along

Score: 0

|

7 didn't require a reboot, even with Office installed.

Score: 2

|

Sadly, Vista couldn't say the same...

Score: 0

|

7 updates on vista sp2 for me

Score: 0

|

i never count the malware removal tool, do you guys?

Score: 0

|

Good point. That makes it 11.

Score: 0

|

Google Chrome 4: Yes, it's fast, but is it usable?

As Betanews readers have responded to our stories about Chrome's JavaScript superiority...Does that mean we'd actually use this browser? Well...

Video: Netflix on PlayStation 3

Netflix has come to the PlayStation 3 via Blu-ray and BD-Live.

Verizon Wireless launches new Android, Chocolate, and ruggedized phones

The lower-priced Eris joins the Droid, while the Chocolate gets a touchscreen and more music playback.

Early sales figures for Windows 7 nicely high, but do we know why?

Fans of triple-digit surges in figures quoted by Betanews will love this one, as it appears Microsoft rediscovered how to pull off a software launch.

Myka announces its latest Linux-based 'net top box'

Myka's ION brings Boxee, XMBC, and much more to HDTVs.

What hath Mac wrought? A remembrance after a quarter-century

The reason there's a Macintosh today is not because of some brilliant flash of engineering genius, but because Apple had the audacity to learn from its mistakes.

Early build of Moblin 2.1 improves connectivity, but not device support

The Linux Foundation's Atom-centric OS yesterday received a major overhaul with the project release of Moblin 2.1 for netbooks and nettops.

The iPhone's China syndrome: Sales of 5,000 and climbing

There's actually a country where Apple's device is not a godsend, where sales can be measured in the dozens.

New European counterpart to FCC will ensure 'a more neutral net'

Late Thursday night, the ruling telecom administrators of the EU's member nations signed away their final authority to a new entity overseen by the EC.

Sophos study suggests Windows 7 UAC's default setting is self-defeating

Without any anti-virus installed, a Sophos test showed, User Account Control was only capable of thwarting just one malware package out of ten samples chosen.

Indiscreet tweet trips awareness of Web SSL vulnerability

A group of high-level security engineers had been making progress on thwarting a low-level threat to the Web, until somebody blurted it all out on Twitter.