- Kindle back orders stretch 3 months at Amazon
- Cisco shutting down between holidays
- Smartphone smackdown: Storm vs. iPhone
- 12 myths about how the Internet works
- Google layoffs: 10,000 jobs being cut
Microsoft Tuesday issued four critical patches to close 10 vulnerabilities, some on critical IT systems such as Active Directory.
The platforms affected by the critical vulnerabilities include Active Directory, Internet Explorer, Host Integration Server and Excel. In all, Microsoft issued 11 patches (see complete list here). In addition to the four that were critical, six were listed as important and one as moderate.
The patches were listed as MS08-056 through MS08-066. (Compare Patch and Vulnerability Management products.)
"There is a nasty bunch of remotely exploited items," says Eric Schultze, CTO of Shavlik Technologies. He says the vulnerabilities this month are centered more on remote execution rather than "visit this evil Web site and get hacked."
"We are getting into more vulnerabilities that hit the infrastructure, the Windows kernel, Active Directory, protocol overflows,"he says. "If you have a Windows 2000 domain controller you are hosed."
In the Active Directory vulnerability, numbered as MS08-060, anyone on a corporate network can send a series of packets to the domain controller and take over the domain. The vulnerability only affects Windows 2000.
"Then they own the domain," Schultze says. "By owning it they then have domain admin privileges, which means they own every laptop and server and desktop in that domain. They can create user accounts, they can delete everybody's user accounts, they can lock everybody off the server, they can delete fields, they can add and delete services and they control everything in the domain."
Another potentially dangerous vulnerability lies in Host Integration Server RPC Service (MS08-059), which is another remote execution bug. The vulnerability covers 2000, 2004 and 2006 version of host integration server.
"Control of HIS can give an attacker control of data flowing into and out of some of the most closely guarded systems on the planet," Sheldon Malm, director of security R&D for nCircle, wrote in a research note. "It is absolutely vital for customers to find and remediate this vulnerability as quickly as possible. Host Integration Server is the de facto gateway linking Windows hosts to business critical mainframes and AS/400 systems, which in turn host databases and Customer Information Control System (CICS) applications that are believed to run in 90% of Fortune 500 corporations."
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comments (2)
Ha HaBy Anonymous on October 15, 2008, 3:17 pm"...They can create user accounts, they can delete everybody's user accounts, they can lock everybody off the server, they can delete fields, they can add and delete...
Reply | Read entire comment
Remote execution vulnerabilities top Microsoft's October Patch TuesdayBy Microsoft Subnet on October 14, 2008, 5:29 pmThis month's batch of Microsoft vulnerabilities are centered more on remote execution rather than "visit this evil Web site and get hacked," said Eric...
Reply | Read entire comment
View all comments