ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Internet Explorer update headlines monster Patch Tuesday

By | April 13, 2011, 10:26am PDT

Summary: In the midst of a wave of zero-day targeted attacks hitting big businesses, Microsoft has shipped a monster batch of security patches to cover 64 vulnerabilities Microsoft Windows, Office, Internet Explorer, Visual Studio, .NET Framework and GDI+. The Internet Explorer browser patch (MS11-018), rated “critical,” covers at least five documents security holes, including one that was used [...]

In the midst of a wave of zero-day targeted attacks hitting big businesses, Microsoft has shipped a monster batch of security patches to cover 64 vulnerabilities Microsoft Windows, Office, Internet Explorer, Visual Studio, .NET Framework and GDI+.

The Internet Explorer browser patch (MS11-018), rated “critical,” covers at least five documents security holes, including one that was used to hijack a Windows 7 machine at this year’s CanSecWest Pwn2Own hacker challenge.

[ SEE: Pwn2Own 2011: IE8 on Windows 7 hijacked with 3 vulnerabilities ]

Of the 17 bulletins released this month, nine and rated “critical,” Microsoft’s highest severity rating.  The remaining eight bulletins carry an “important” rating, which means they can be exploited to result in compromise of the confidentiality, integrity, or availability of users data, or of the integrity or availability of processing resources.

Microsoft is urging Windows users to treat the following bulletins with the utmost priority:

  • MS11-018 (Internet Explorer). This security bulletin resolves four privately reported vulnerabilities and one publicly disclosed vulnerability in Internet Explorer. This bulletin is rated Critical for IE 6, IE 7 and IE 8 on Windows clients; and Moderate for IE6, IE7, and IE8 on Windows servers. Internet Explorer 9 is not affected by the vulnerabilities. Microsoft is aware of limited attacks leveraging vulnerabilities addressed by this bulletin, including the vulnerability used at the CanSecWest 2011 Conference, which we tweeted about yesterday. We encourage all customers apply this bulletin first of all our April bulletins. We encourage all customers apply this bulletin first of all our April bulletin.
  • MS11-019 (SMB Client). This bulletin resolves one publicly disclosed vulnerability and one privately reported vulnerability in Microsoft Windows. The vulnerabilities could allow remote code executions if an attacker sent a specially crafted SMB response to a client-initiated SMB request. The publicly disclosed vulnerability was posted to full disclosure on February 15. Microsoft investigated the issue and found that remote-code execution was extremely unlikely. As Microsoft has not seen any active attacks, we opted not to disrupt customers with an out-of-band bulletin.
  • MS11-020 (SMB Server). This bulletin resolves an internally discovered vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if an attacker created a specially crafted SMB packet and sent the packet to an affected system.

Microsoft also released a two new tools – Rootkit Evasion Prevention tool and Office File Validation to beef up the security of its Office produce line.

According to Wolfgang Kandek of Qualys, all Windows operating systems and all versions of Office are affected by this Patch Tuesday, making it a “full plate for system administrators of companies both large and small.”

In addition the three high-priority updates listed above, Kandek also calls attention to  MS11-021, MS11-022, MS11-023 — vulnerabilities in the Microsoft Office Suite.

Rodrigo Branco, Director of Vulnerability Research at Qualys who reported the Excel vulnerability fixed by MS11-021 to Microsoft in 2010, emphasizes that an attacker can relatively easily craft an Excel file that will trigger the flaw. He recommends installing this patch as quickly as possible.

Noting that ongoing attacks against Adobe Flash vulnerabilities are being used in the wild to attack workstations, Kandek recommends that IT administrators look into the possibility of disabling Flash content in Word or Excel files.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues.

Disclosure

Ryan Naraine

The most important disclosure is of my employment with Kaspersky Lab as a member of the global research and analysis team. Kaspersky Lab is a global company specializing in anti-malware and secure content management technologies. I do not own stocks or other investments in any technology company.

Biography

Ryan Naraine

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues. He is currently security evangelist at Kaspersky Lab, an anti-malware company with operations around the globe. He is taking a leadership role in developing the company's online community initiative around secure content management technologies.

Prior to joining Kaspersky Lab, Ryan was Editor-at-Large/Security at eWEEK, leading the magazine's and Web site's coverage of Internet and computer security issues and managing the popular SecurityWatch blog, covering the daily threats, vulnerabilities and IT security technologies. He also covered IT security, hacker attacks and secure content management topics for Jupiter Media's internetnetnews.com.

Ryan can be reached at naraine SHIFT 2 gmail.com. For daily updates on Ryan's activities, follow him on Twitter.

22
Comments

Join the conversation!

Just In

RE: Internet Explorer update headlines monster Patch Tuesday
FAULKNE 13th Oct
Good day to confirm this comment I would appreciate T h e b e s t o f Z D N e t d e l i v e r e d your website very nice to everyone Yes, Oracle is the only one with shared-disk architecture, but that is there advantage. It means you can add or remove nodes and the database lives on. In a shared nothing architecture, if you lose a node, you lose the system. I'm sure Oracle appreciates EMC highlighting their advantage.I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate Awesome post! Thank you very much || thanks for nice content this is really benefit to me.
"Internet Explorer 9 is not affected by the vulnerabilities."

Next.
Thank you and good luck everyone! replica hermes bags
0 Votes
+ -
...you'll be alright. Its interesting, I have never been exploited by any one of these critical vulnerabilities. My machine must not be sexy enough to hack. Then again, that would 1.2 billion Windows machines are not sexy enough to hack.
Especially the vulnerability fixed by patch number MS11-032. IMO this is the most critical patch to deploy.
ANY operating system is as vulnerable as the last person who logged off. Thinking otherwise is idiocy.
Is the cumulative security update a combination of all the individual patches?
0 Votes
+ -
Was prompted for the downloads the other day, it couldn't have been any easier to install. With Microsoft's automatic updates its just a one click process that allows you to keep your systems up to date.
0 Votes
+ -
Domain Wide Disable Flash in Office Files
jthomas@... 14th Apr 2011
Can anyone suggest a resource for "disabling Flash content in Word or Excel files" using something like GP within the domain?
0 Votes
+ -
Gotta Start Loving 2011
MrElectrifyer Updated - 14th Apr 2011
It has been really shinning the light in the eyes of several unix derivative noobs. It has opened their stony heads to the truth " No man mad OS is immune to malware nor nasty hackers".

In the past years, when ever there was a small talk about critical vulnerabilities in Windows, I see dozens of noobish comments from the Unix Derivativ fanboys (especially "...your linux advocate" wink ) about how other OS are immune to malware.

Keep it up 2011, you're making good history grin
Great!!! thanks for sharing this information to us!

sesli chat sesli sohbet
This is an excellent article. The following publish supplies genuinely high quality info. My spouse and i?meters bound to check in it. Truly extremely helpful points are given listed here. Many thanks a great deal. Carry on favorable functions. vintage snapback hats best solid state drive
This is a really good read for me. Must admit that you are one of the best bloggers I have ever read. Thanks for posting this informative article. baby gifts for boys baby gifts for girls
I like the article you wrote here; it is very informative and useful for the internet users like me. I will come back to read more blog posts on your website and I have bookmarked your website as well Thank You know style clothing store girls clothing stores online
I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate! nccma cooler
I used to be more than happy to seek out this internet-site.I wanted to thanks in your time for this glorious read!! I positively enjoying each little bit of it and I have you bookmarked to check out new stuff you weblog post. this thread is amazing i like your work and i appreciate you that you have share a useful stuff thanks for sharing the i shop abatwa
I used to be more than happy to seek out this internet-site.I wanted to thanks in your time for this glorious read!! I positively enjoying each little bit of it and I have you bookmarked to check out new stuff you weblog post.Bookmarking now thanks please consider a follow up post. power sa shop
I think the representation of this article is actually superb one. This is my first visit to your site. Thanks a lot and keep sharing the information. Keep updating the information for all of us. Thanks ZDNet Government was launched as the brand's first industry vertical, with a mission to cater to IT professionals in the public secto I agree with your post. However, do you have any sources I can cite for my paper wheel car com bury
Well welcome, hopefully you can become a vital member of the community and really help to push far ahead of google. Which Im sure the development team would love. This will of course earn you alot points too and get you on the leaders board. z d n e t t h a n k Im not sure i come to an agreement with you on every level, howevor it absolutely was a good posting, many thanks for taking the time to put up your ideas.
This is my first visit to z d n e t site. Thanks a lot and keep sharing the information. Keep updating the information for all of us.how can i clean up, because i don???t know why it seems my skeen has to fat i get the glasses dirty every day.i search y a h o o Very good quality indeed. I surely recommend it. The template used in their site is also great.
Fantastic news about the new release.I positively enjoying each little bit of it and I have you b o o k m a r k e d to check out new stuff you weblog post.Im not sure i come to an agreement with you on every level, howevor it absolutely was a good posting, many thanks for taking the time to put up your ideas
Good day to confirm this comment I would appreciate T h e b e s t o f Z D N e t d e l i v e r e d your website very nice to everyone Yes, Oracle is the only one with shared-disk architecture, but that is there advantage. It means you can add or remove nodes and the database lives on. In a shared nothing architecture, if you lose a node, you lose the system. I'm sure Oracle appreciates EMC highlighting their advantage.I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate Awesome post! Thank you very much || thanks for nice content this is really benefit to me.

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix