Microsoft Remedies 14 Flaws in Nine Patches

By Ed Oswald | Published August 14, 2007, 4:23 PM

Microsoft fixed a total of 14 flaws across 9 patches on Tuesday, with six of those patches reaching critical status. While the number of patches is far from the Redmond company's record, this month could prove difficult for administrators.

"This month's Patch Tuesday has headache written all over it," PatchLink's Paul Zimski commented. "Although this is not Microsoft's biggest Patch Tuesday in terms of number of patches, the details of the patches indicate a broad-spectrum of exposure."

Of the critical patches, all deal with remote code execution issues. The first patch fixes issues within the XML Core Services of Windows, while another corrects a memory corruption issue within the Object Linking and Embedding function in Windows, Visual Basic, and Office for Mac.

A third critical patch fixes a workspace memory corruption flaw within Excel, and issues in how the Graphics Rendering Engines handles specially crafted images have also been remedied.

Two critical patches for Internet Explorer were also released; one that fixes a buffer overrun vulnerability within Vector Markup Language, as well as a cumulative patch that contains three separate fixes for two ActiveX Object problems and a CSS memory corruption issue.

Three important patches are available as well: two for remote code execution issues and one that involves elevation of privilege. In addition, a fix for Windows Media player repairs two separate issues with the parsing and decompressing of skins used to change the look of the player.

Also fixed was an issue within Windows Vista concerning the "gadgets" feature. Microsoft says that malicious files could open the operating system up to remote code execution. Finally, a flaw in Virtual PC and Virtual Server that could result in elevation of privilege was also remedied.

"Organizations need to remediate these vulnerabilities as quickly as possible to avoid falling victim to quick turnaround exploits," Zimski said.

Comments

Jeez Louis! Remote code running through the GDI!?!

Score: 0

|

The inclusion of the optional Logitech camera software update was very poorly implemented. My computer's left hand had absolutely no idea of what its right hand was doing.

First, Logitech downloaded and supposedly installed from M$ update. However, there is then a Logitech updater which demands you to manually go thru the installation again. That procedure also asks for your original Logitech v.10 program disc. (That instruction can be ignored. Just click on thru.)

And even after all of that confusion, on one of my systems the update still had not taken hold. Why can't Microsoft get something right that it has been doing for a couple of years now?

Advice: Install the Logitech upgrade manually--since that's what you end up doing anyway.

Score: 0

|

How are IT departments supposed to keep up with these patches?

Firms that have any kind of standards (especially those that follow the ITIL system) have to perform testing for these patches and so can't afford to blindly deploy patches and take the chance on issues arising as a result.

Such firms are likely to be months out of date with what Microsoft are spitting out!

Score: 0

|

If you're using Windows, you're more than months out of date!
(grin)

Score: 0

|

Several options:

1. In smaller environments, you can turn on auto-updates. In larger environments with all kinds of configs, this might not be the best option as you stated.
2. MS gives you the option of standing up your own update server. Once you 'approve' each patch, then it gets pushed to all your client servers and desktops at the time you specify. Very simple process. You can redirect all clients to your update server via a policy. No need to visit each machine.

Patches are a way of life regardless of platform. You need to develop a policy and stick with it.

Score: 0

|

Before it can tackle Windows, Chrome must leave Safari in the dust

It's a little browser with dreams of becoming a bigger operating system some day. But while it's chasing Microsoft's dreams, Chrome's tail is being chased by Apple.

Silverlight 3 goes live on Microsoft's servers

Microsoft's answer to Adobe's Flash is (unofficially) here, with prospects of higher-speed, higher-resolution video and for the first time, 3D.

Best Buy-brand TVs to get TiVo

A new alliance will place the retailer's own brand alongide the manufacturers, and could also lead to future partnerships on services.

Three Android phones on the way from T-Mobile in 2009

T-Mobile's myTouch 3G, launched Wednesday, will be followed by two more Android phones later this year, but neither of them will be HTC's Hero.

LTE still lacks a voice

The 4G Wireless standard that Verizon hopes to show off before this year is out is still at a loss for (spoken) words.

T-Mobile's strategy to combat Apple's iPhone with Android

With a trio of Android phones now in the pipeline for 2009, T-Mobile hopes to break the iPhone's emerging stranglehold.

EC's Reding: Government should act as broker for media downloads

If Internet media services don't step up and build an attractive way for users to start paying for downloads, a commissioner says, government may do the job instead.

Sony TVs get Netflix, still no PS3

Though it's coming in behind LG, Samsung, and Microsoft, Sony will begin to offer Netflix streaming, too.

Google Chrome OS: Too little, too early

Carmi Levy: Wide Angle Zoom Don't start the revolution just yet, says Carmi, who isn't so certain Chrome OS will be the "Windows Killer."

GAO pen test brings the hammer down on federal rent-a-cops

But are the computers to blame for the contract-guard fiasco at FPS?

What's Next: Chrome OS will have at least some friends in high places

Also: South Korea takes another round of DDoS abuse, and Neelie Kroes and Steve Ballmer may shake hands before she exits stage left.

Data sharing among online advertisers: Is sanity in sight?

Lockdown with Angela Gunn In the middle of a 15-page plea not to get regulated, a spark of smart thinking.

PST Recovery Software 12.0

July 9 - 11:34 PM ET

Unistal Data Recovery 12.08.06

July 9 - 11:09 PM ET

BKF Repair 3.0

July 9 - 10:54 PM ET

Vuze for Windows 4.2.0.4

July 9 - 6:26 PM ET

UltraVNC 1.0.6.4

July 9 - 6:05 PM ET

WildBit Viewer 5.5 Beta 3.0

July 9 - 5:44 PM ET