Microsoft on Tuesday patched 20 vulnerabilities, more than half of them rated critical, in 11 separate security updates for Windows, Office, Internet Explorer (IE), Active Directory and the Host Integration Server.
Also for the first time, the company predicted the likelihood that hackers would come up with exploits for each bug.
"The count's big," said Andrew Storms, director of security operations at nCircle Network Security Inc. Eleven of the 20 flaws were rated "critical," the top ranking in Microsoft's four-level threat scoring system, while eight were pegged as "important," the next step down, and one was listed as only "moderate." Tuesday's update was the largest since August, when Microsoft issued 26 patches in 12 bulletins.
Storms identified two general themes in the latest round of patches. "First, there's still a pervasiveness of client application updates that doesn't seem to be diminishing at all, and second, Microsoft's newer software is still less vulnerable than its older."
On the first point, Storms ticked off updates that addressed three critical vulnerabilities in Excel and six critical bugs in IE , while for the second he listed several security bulletins that tagged Windows 2000 or older editions of Office as vulnerable, but gave newer versions of its operating system or applications either a pass or lowered the threat for users.
"Today's patches really continue to hammer the idea that the newer [Microsoft] software is more secure," said Storms. "If there was ever a reason to update to newer software, this is it. There's no reason not to update, for example, to IE7."
Storms highlighted two other updates that he thought should receive special attention, particularly by enterprise IT professionals. One, spelled out in MS08-060 , affects Active Directory, while the other, MS08-059 , affects Host Integration Server (HIS), a little-known corporate product that connects Windows-based networks to IBM mainframe and AS/400 systems. Microsoft marked both bulletins as critical.
"The attack surface is low for MS08-059, but the potential impact is high because HIS interacts with the critical back-office infrastructure that can't be down," said Storms. Tuesday's patch was the first ever for HIS, a fact that didn't escape Storms. "Now there's an update that will affect administrators who probably wanted nothing to do with Microsoft," he said.
"And there will be a lot of discussion about the Active Directory vulnerability as well as the SMB bug , mainly because these are remote exploits," Storms said. "They're in the classic style, where just some data packets can compromise systems. For that reason, I think they will garner a fair amount of respect, and researchers will probably exploit that."
Microsoft also used Tuesday's updates to launch its "Exploitability Index," a new effort announced in August . The index, which can be found in October's summary , lists each vulnerability along with the company's exploit rating. Microsoft settled on a three-step system that, in descending order of severity, predicts that researchers or hackers will come up with a consistently working exploit, develop an exploit that works only some of the time, or fail to craft attack code at all.
The inaugural index pegged eight of the month's 20 vulnerabilities with "Consistent exploit code likely" label, seven with the "Inconsistent exploit code likely" tag and four with "Functioning exploit code unlikely."
References
- Microsoft readies first attack forecast
- Upcoming Microsoft patch lineup could be 'massive'
- Technet security bulletin MS08-057
- Technet security bulletin MS08-058
- Technet security bulletin MS08-060
- Technet security bulletin MS08-059
- Technet security bulletin MS08-063
- Microsoft readies first attack forecast
- Technet October summary
- Xforce - IE vulnerability
- technical description
- Technet ActiveX advisory
- Microsoft: Ask us and we'll kill your ActiveX control
Latest on Services
- Efficiency key to Avaya's success, Giancarlo says
- Seven Lessons That SMBs Can Learn from Big IT
- It takes a quality IT group to deliver good yogurt
- Greens accuse Conroy of fudging facts over content filter trials
- Is our Internet future in danger?
- Education in 2015: Cyberlearning for digital natives
- Drive the goblins out of your converged network
- Juniper WXC 1800 speeds WAN traffic
- Cisco VAR case signals changes to come
- Managing in mixed environments
Networking Essentials
- Efficiency drive moves to networks
- NEC's ExpEther extends PCI Express over Ethernet
- Researchers caution against TCP/IP weakness
- 10G Ethernet: can copper cut the mustard?
- 25 network research projects you should know about
- Big changes ahead for the Internet, says Vint Cerf
- Cisco routers out, Juniper gear in at Amazingmail.com
- What's hot at Interop 2008
- Optical networking a $US12 billion business: Ovum
- Brocade to buy Foundry for US$3 billion
TechWorld Jobs (beta)
Recent Jobs
TechWorld Blogs
-

TalkingTech
The view from the top of IT with TechWorld Editor Rodney Gedda
-

Entrenched
Cooking up better code, IDG's developers reveal some of their secrets
-

Broadband Voice
Darren Pauli digs in from the front line of Australia's broadband battleground
Recent blog posts
- A Novell approach to business
- An open storage stack? I like the sound of that
- The mobile clone wars: fighting for a better phone experience
- Stopping the "Clean Feed"
- Identifying web platforms
- Clean Feed ‘not technically possible’
- No Clean Feed - well duh!
- Conroy's content cops still on the cards
- Will open source ruin the economy? Please help
- Linux kernel 2.6.27 is out!
Recent comments
- Hello this is Brianna
21 hours 51 min ago - Turn any PC into a media center
1 day 11 hours ago - How About the Correct Title?
2 days 2 hours ago - who are you kidding?
2 days 8 hours ago - Seriously, how much did they pay for this advertisement
3 days 22 hours ago - SF Bay Area - free Seminar on Enterprise Cloud Computing
4 days 2 hours ago - video conferening but not telepresence...
4 days 9 hours ago - SAMSUNG OLED 40" TECHNOLOGY
4 days 17 hours ago - What was the question again, oh well this was prepared earlier
1 week 50 min ago - Worldwide broadband prices continue to drop which means ? in AU
1 week 1 hour ago - Not a Problem Here in Australia and New Zealand
1 week 2 days ago - Clear the air
1 week 3 days ago - Tabbed browsing, Quick Find,
1 week 5 days ago - Microsoft details plans for new social bookmarking tool
2 weeks 29 min ago - There is a 3rd party tool
2 weeks 1 day ago - Demise of Windows
2 weeks 1 day ago - new OS
2 weeks 1 day ago - Re: Favicon
2 weeks 3 days ago - Multi Camera Kino
2 weeks 3 days ago - Favicon
2 weeks 4 days ago



