Salted Hash — IT security news

About this Blog:

IT security news analysis, over easy!

Bill Brenner

Patch Tuesday preview for December

to Data Protection |
Expect 14 security updates from Microsoft Tuesday -- three of them for critical vulnerabilities.

Microsoft made the announcement in its advance notification message Thursday afternoon.

According to a quick analysis from vulnerability management vendor Qualys:

--The updates will affect Windows XP, Vista, and Windows 7. Only one of the critcal vulnerabiilties applies to Windows 7. On the server side, both Windows 2003 and 2008 are vulnerable, but again the newer 2008 is better than 2003, with only one vulnerability applicable.

--Five of the "important" bulletins affect Office 2003, 2007 and 2010 including all office versions for Macintosh as well. One of the remaining bulletins addresses Internet Explorer 6 through 9 and the remaining bulletins apply to all versions of Windows.

--Adobe Reader 9 users can expect an update to address the current zero-day vulnerability in Reader (and Acrobat itself).

Alex Horan, senior product manager at Core Security, made this observation in an email Thursday afternoon:

"Attackers will be drawn to the three critically rated vulnerabilities, as well as the four Remote Code Execution vulnerabilities in the Microsoft Office products. Code Execution in Office provides fresh Client Side exploit capabilities, which may have a long shelf live, given the delay administrators take in pushing patches out to users’ machines for fear of causing issues with their users ability to work.”

--Bill Brenner



CSO's Daily Dashboard gives you a one-stop view of latest business threats. We created it for you! Bookmark it! Use it!






Print
What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
WHITE PAPER
Reduce Email Archives up to 60%

Clearwell Are you considering implementing a proactive archiving and eDiscovery solutions? This paper summarizes 15 separate soft cost savings when implementing Symantec Enterprise Vault and the Clearwell eDiscovery Platform.

» Learn More

WHITE PAPER
Aberdeen Report: To Patch, or Not to Patch? (Not If, But How)

Secunia The report explores the correlation between the current use of patch management and the level of endpoint-related risk that companies are effectively accepting.

» Learn More

Browse CSO Blogs

See all CSO Blogs »

Recent Comments

RESOURCE CENTER