Microsoft Remedies 14 Flaws in Nine Patches

By Ed Oswald | Published August 14, 2007, 4:23 PM

Microsoft fixed a total of 14 flaws across 9 patches on Tuesday, with six of those patches reaching critical status. While the number of patches is far from the Redmond company's record, this month could prove difficult for administrators.

"This month's Patch Tuesday has headache written all over it," PatchLink's Paul Zimski commented. "Although this is not Microsoft's biggest Patch Tuesday in terms of number of patches, the details of the patches indicate a broad-spectrum of exposure."

Of the critical patches, all deal with remote code execution issues. The first patch fixes issues within the XML Core Services of Windows, while another corrects a memory corruption issue within the Object Linking and Embedding function in Windows, Visual Basic, and Office for Mac.

A third critical patch fixes a workspace memory corruption flaw within Excel, and issues in how the Graphics Rendering Engines handles specially crafted images have also been remedied.

Two critical patches for Internet Explorer were also released; one that fixes a buffer overrun vulnerability within Vector Markup Language, as well as a cumulative patch that contains three separate fixes for two ActiveX Object problems and a CSS memory corruption issue.

Three important patches are available as well: two for remote code execution issues and one that involves elevation of privilege. In addition, a fix for Windows Media player repairs two separate issues with the parsing and decompressing of skins used to change the look of the player.

Also fixed was an issue within Windows Vista concerning the "gadgets" feature. Microsoft says that malicious files could open the operating system up to remote code execution. Finally, a flaw in Virtual PC and Virtual Server that could result in elevation of privilege was also remedied.

"Organizations need to remediate these vulnerabilities as quickly as possible to avoid falling victim to quick turnaround exploits," Zimski said.

Comments

View comments by with a score of at least

Jeez Louis! Remote code running through the GDI!?!

Score: 0

|

The inclusion of the optional Logitech camera software update was very poorly implemented. My computer's left hand had absolutely no idea of what its right hand was doing.

First, Logitech downloaded and supposedly installed from M$ update. However, there is then a Logitech updater which demands you to manually go thru the installation again. That procedure also asks for your original Logitech v.10 program disc. (That instruction can be ignored. Just click on thru.)

And even after all of that confusion, on one of my systems the update still had not taken hold. Why can't Microsoft get something right that it has been doing for a couple of years now?

Advice: Install the Logitech upgrade manually--since that's what you end up doing anyway.

Score: 0

|

How are IT departments supposed to keep up with these patches?

Firms that have any kind of standards (especially those that follow the ITIL system) have to perform testing for these patches and so can't afford to blindly deploy patches and take the chance on issues arising as a result.

Such firms are likely to be months out of date with what Microsoft are spitting out!

Score: 0

|

If you're using Windows, you're more than months out of date!
(grin)

Score: 0

|

Several options:

1. In smaller environments, you can turn on auto-updates. In larger environments with all kinds of configs, this might not be the best option as you stated.
2. MS gives you the option of standing up your own update server. Once you 'approve' each patch, then it gets pushed to all your client servers and desktops at the time you specify. Very simple process. You can redirect all clients to your update server via a policy. No need to visit each machine.

Patches are a way of life regardless of platform. You need to develop a policy and stick with it.

Score: 0

|

Betanews Podcast: Transportation security, Facebook sensitivity, and you

Putting a big, black rectangle around stuff you don't want people to see, isn't exactly making it private. Facebook's equivalent is perhaps no better.

The PDF redaction problem: TSA may have been using old software

Betanews tests and research reveals that if the Transportation Security Administration was using modern software, it might not have a security issue now.

Google Maps doesn't prevent car accidents, only search accidents

This week, Google updated Maps for Android 3.3.1, adding topography, nearby points of interest, and error reporting.

The $1 DVD rental debate: LA group says Redbox will lose movie makers $1B

A report from the Los Angeles Economic Development Corporation says cheap Redbox DVD rentals could seriously damage the movie business.

iTunes gets cloudy: Will a web-ified future save iTunes or kill it?

Carmi Levy | Wide Angle Zoom: Apple reportedly wants customers to consider trading in a pod for a cloud.

Third-party mobile browsers Skyfire and Bolt give Opera a run for its money

Opera may be the biggest name in third party mobile browsers, but Skyfire and Bolt are charging forth with compelling updates.

In a peace offering to newspapers, Google offers a new news format

It's probably not a solution to the woes of major news publishers, but Living Stories may gather a few of those publishers together in search of one.

DOJ: Microsoft interop docs are now 'substantially complete'

A major milestone in the US Government's oversight of Microsoft is passed, as the Justice Dept. is now saying the company's protocol documents make sense.

First impressions of Droid: Easy, breezy, friendly, if a little fat

Though it's not quite as well-polished as Apple's iPhone OS, the version of Android that Motorola's Droid phone sports is still a breeze to use.

After telling US to mind its own business, Kroes slaps caps on Rambus royalties

The holder of many patents worldwide pertaining to DDR memory offered to reduce its royalty stake in that technology, and today the EU said yes.

EC's Kroes to US senators: Mind your own business on Oracle + Sun

UPDATED The EU's antitrust chief told the United States Senate Tuesday that any merger that takes place in the world is more her affair than theirs.