On CHOW: Sexy vampire party
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Lemos
Posted on ZDNet News: Nov 11, 2003 8:36:00 PM

Microsoft released three security updates for the Windows operating system and one update for Office, leaving many federal system administrators with no choice but to work on a U.S. national holiday.

The three Windows updates, announced Tuesday, are ranked as "critical," Microsoft's highest rating on the seriousness of security flaws. The updates fix at least eight security issues. The Office update--required for Office 97, 2000 and XP but not 2003--fixes two flaws in the popular productivity program.

"One of the things that we kind of did in this case is that we included several patches in some of the fixes," said Stephen Toulouse, security program manager for Microsoft's security response center.


Get Up to Speed on...
Enterprise security
Get the latest headlines and
company-specific news in our
expanded GUTS section.


"We are trying to drive the deployment of fixes for our customers. It is one of the things our customers have asked us to do."

The updates are the second installment since Microsoft revamped its patch publishing schedule to release fixes on the second Tuesday of every month. The November release, however, is problematic in the United States, because this year, the second Tuesday is Veterans Day. Foreseeing that the release might pose a problem for federal administrators, the Federal Computer Incident Response Center (FedCIRC) sent an e-mail to many U.S. agencies, warning their network custodians that the patches are coming out.

"FedCIRC has coordinated with Microsoft on the release of four Microsoft security bulletins," the e-mail stated. "They will be released tomorrow, Veterans Day, 11 November 2003. Please keep an eye out for them and consider the (effect) that they may have on your infrastructure."

Perhaps the most serious flaw is a memory error in the Windows Workstation service, a software component that facilitates access to network resources such as printers and files. The vulnerability could allow an attacker to gain control of a person's PC via the Internet in much the same way the MSBlast worm was spread to hundreds of thousands of computers in August.

The patches fix several flaws in Internet Explorer that could allow an attacker to compromise a person's PC by drawing the user to a Web site designed for that purpose or with an e-mail, if the victim is using an unpatched version of Outlook 98 or Outlook 2000. Called cross-domain vulnerabilities, the flaws affect Internet Explorer 5.01, 5.5 and 6 on every Windows platform, except for Windows Server 2003. That latest version of Microsoft's enterprise operating system has default settings that limit the effect of the flaws.

The move to monthly patches has garnered some criticism from security experts.

"Microsoft wants to make it easier for administrators, but it's more likely that the bad guys are going to release the patches the following week," said Richard Forno, an independent security consultant.

The regular patch publishing schedule may inspire more corporate system administrators to upgrade their systems, but it will also allow underground programmers a predictable time to focus on writing code to exploit the flaws, he said.

For that reason, Forno believes the move is more likely about minimizing the number of times Microsoft flaws are covered in the press.

"It think it is more to get Microsoft's name out of the news," he said. "It is good marketing but lousy security."

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 67 Talkback(s)
ZZ: yes, exactly like that...
'the only reason i support the dems a bit more than the republicans are more for issues like abortion and religous fundimentalism (which i find more common in republicans)...'

I can support the... (Read the rest)
Posted by: Dave P. Posted on: 11/13/03 You are currently: a Guest | | Terms of Use
MS plans distraction campaign  Chad_z | 11/11/03
Less credibility than Bush?  Damon K | 11/11/03
Oh, please  frgough@... | 11/11/03
Do you..  CooCooCaChooNZ | 11/11/03
Bush bashers are funny  Dave P. | 11/11/03
Runaway intelligence is smart?  Still Lynn | 11/12/03
Runaway intelligence is smart?  hal9000mx | 11/12/03
hal9000mx: Runaway intelligence is smart?  Dave P. | 11/13/03
But sycophants are downright hilarious  Fred Fredrickson | 11/12/03
However...  Dave P. | 11/13/03
re: Bush bashers are funny - but Bush apologist make me giggle  bgoss@... | 11/12/03
Speaking of Apologists  Dave P. | 11/13/03
explain then...  ryusen | 11/12/03
specific please  Dave P. | 11/13/03
my memory is vague  ryusen | 11/13/03
Wow, with proof like that...  Dave P. | 11/13/03
REAL People?  samp_z | 11/12/03
get real  Suicida| | 11/12/03
Well, at least one thing you said was true...  Damon K | 11/11/03
sigh...  Dave P. | 11/11/03
RE: sigh...  hal9000mx | 11/12/03
RE: Sigh...  middle of nowhere | 11/12/03
ZDNet, fix your forums! This is to "middle of nowhere."  Damon K | 11/12/03
re: middle of nowhere  ryusen | 11/12/03
you mean like  Dave P. | 11/13/03
yes, exactly like that...  ryusen | 11/13/03
ZZ: yes, exactly like that...  Dave P. | 11/13/03
Ahh, it's all Clinton's fault....  Damon K | 11/12/03
This is too easy!  Dave P. | 11/13/03
RE: Oh, please  hal9000mx | 11/12/03
Check out the web...  Dave P. | 11/13/03
sigh...  Dave P. | 11/11/03
Gasp!!  Still Lynn | 11/12/03
Wow, Bush sure is a quiet man.  Damon K | 11/12/03
Was WAS neccessary  Dave P. | 11/13/03
What does this have to do with anything?  ShadeTree | 11/13/03
Personally  Dave P. | 11/13/03
M$ is screwing people again!  screaming silence | 11/11/03
yes those evil evil bad men...  Joe_Bob | 11/11/03
Does it matter?  zd-spam | 11/11/03
No it doesn't matter  gilgamesh_z | 11/11/03
re: yes those evil evil bad men...  altereqo | 11/11/03
You must enter a title for your message:  Still Lynn | 11/12/03
Oh, do be quiet. These trolls are getting old. (n/t)  Damon K | 11/11/03
MS, friend of the working person  MalumRegnat | 11/12/03
Not Exactly!  ShadeTree | 11/13/03
unlucky for those on dial-up  Iain_Peters | 11/11/03
Friend of the sub-normal  MalumRegnat | 11/12/03
Stop thinking like a computer guy  Arrg | 11/12/03
Interface Design  scredge | 11/13/03
i like it  lmaxwell | 11/11/03
You know...  prime21 | 11/11/03
Not precisely true, but close...  Damon K | 11/11/03
Non event for this CIO  Mike Cox | 11/11/03
You and your MCSEs  nucrash | 11/12/03
yes  Mike Cox | 11/11/03
Kudos to the Redmonians  theo_durcan | 11/11/03
So True  altereqo | 11/11/03
Microsoft and it monopoly  hal9000mx | 11/11/03
Windows Update  nucrash | 11/12/03
WORKING ON A HOLIDAY  wiskowst | 11/12/03
Federal Workers  samp_z | 11/12/03
What if Detroit was like Microsoft  Grastar | 11/12/03
Consider the alternative.  PsykoPup | 11/13/03
I'm a little disappointed, people.  tlciii | 11/12/03
Microsoft fixes  rjk_z | 11/12/03
Don't patch too soon  scredge | 11/13/03

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

Meet Doc