Patch Tuesday notes, February 2012
Microsoft has just released its February 2012 security updates. Here's some analysis from the folks at Symantec, McAfee and Qualys.
From McAfee:
Microsoft Patch Tuesday for Valentine’s Day 2012 brings nine security bulletins for 21 vulnerabilities, affecting Microsoft Windows, Microsoft Office, the Internet Explorer browser and .NET/Silverlight. There are four bulletins that are rated “critical,” and five rated as “important.”
"This month’s Patch Tuesday is relatively light,” said Jim Walter, manager of the McAfee Threat Intelligence Service (MTIS) at McAfee Labs. “The Internet Explorer bulleting should be considered a top priority, as there’s a risk of code execution attacks. If not attended to, browser exploits can be particularly harmful.”
“Adobe also released two updates today,” adds Walter. “Nine ‘critical’ patches were released for the Shockwave Player for Windows and Mac and one ‘important’ in Robohelp. “
From Symantec:
“Six of the patches this month are marked as critical, the most we’ve seen in a while,” said Joshua Talbot, security intelligence manager, Symantec Security Response. “While all these vulnerabilities should be patched as soon as possible, we recommend paying particular attention to the HtmlLayout vulnerability and the GDI Access Violation vulnerability, both of which allow for remote code execution.”
“It is important to note that the GDI Access Violation vulnerability was made public in December of last year,” Talbot added. “While exploit attempts so far have only resulted in denial of service attacks, there is a possibility that it can result in a full system takeover, which is of course the ultimate goal for attackers.”
“Exploits for both of these vulnerabilities are likely to be hosted as drive-by downloads on maliciously created or otherwise compromised websites. So, as always we strongly advise avoiding sites of unknown or questionable integrity to protect from attacks seeking to use these security holes.” Talbot concluded.
From Qualys:
It turns out that this February Patch Tuesday is lighter than we had anticipated. Some of the nine bulletins should be less worrisome to IT admins: the Office vulnerability (MS12-015) is in the relatively rare Visio viewer program, MS12-011 is an XSS vulnerability in Sharepoint and MS12-014 and MS12-012 cover DLL preloading vulnerabilities, one in the now deprecated Indeo Codec and the other one in the Color Control Panel. By the way, both are prevented by the recommended work-around for DLL preloading attacks (KB2264107), released in June 2010, which you should have installed already.
Not all of the bulletins are quite so harmless though: MS12-010 fixes four vulnerabilities in Internet Explorer, which have the potential to be used for drive-by-download exploits on IE 7,8 and 9. Last month we have seen how quickly attackers can react to new vulnerabilites when exploits for MS12-004 appeared with 2 weeks of its release on attack sites. So while none of the vulnerabilities in MS12-010 were publicly known, you should install this fix as quickly as possible.
MS12-013 is equally dangerous; attackers can exploit a flaw in a Windows DLL (msvcrt.dll) through a maliciously crafted media file run through Windows Media Player. Include this bulletin in your list of high priorities.
MS12-016 should be considered by users of .Net framework and Silverlight and is applicable to both PCs and Macs. Users browsing to malicious webpages can be affected and allow remote code execution. Server administrators should take a look as well: if their users are allowed to upload their own ASP.NET files to run on the machine and if the server runs under a Full Trust setting, the attacker could break out of the ASP.NET sandbox and take control of the server.
Lastly, MS12-009 addresses a vulnerability first blogged about in December 2011 in 64bit Windows 7. A security researcher with the handle w3bd3vil found the flaw through Apple's Safari browser where an overly large IFRAME height attribute causes a crash in the kernel driver win32k.sys. Microsoft believes it is difficult to engineer the code to achieve remote control execution and gives it an exploitability index of 2. Nevertheless you should address it if you are running under that configuration.
Reduce Email Archives up to 60%
Are you considering implementing a proactive archiving and eDiscovery solutions? This paper summarizes 15 separate soft cost savings when implementing Symantec Enterprise Vault and the Clearwell eDiscovery Platform.
Aberdeen Report: To Patch, or Not to Patch? (Not If, But How)
The report explores the correlation between the current use of patch management and the level of endpoint-related risk that companies are effectively accepting.
Recent Comments
- The CISO's Survival Guide to Securing Data
- Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
- FireEye Advanced Threat Protection KnowledgeVault
- Five Tips to Consider in a Data Security Strategy for Smartphones and Tablets
- Moving Your Email to the Trusted Cloud
- Comprehensive Server Protection

