On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Lemos
Posted on ZDNet News: Oct 12, 2004 7:28:00 PM

Microsoft on Tuesday published 10 software security advisories, warning Windows users and corporate administrators of 22 new flaws that affect the company's products.

The advisories, and patches published with the bulletins, range from an "important" flaw affecting only Microsoft Windows NT Server to a collection of eight security holes, including three rated "critical," that leave Internet Explorer open to attack. Microsoft's highest severity rating for software flaws is its "critical" ranking, while "important" is considered slightly less severe.

One flaw, in Microsoft Excel, even affects Apple Computer's Mac OS X.

The abundance of flaws could leave corporate PCs vulnerable to attack if administrators are not able to patch quickly. A similar situation occurred in April, when Microsoft published seven advisories detailing 20 flaws. While one security hole stood out among those 20--and led to the widespread Sasser worm--there are no standouts in the current gaggle of goofs.

"Our challenge is trying to guess what the criminals are going to attack," said Stephen Toulouse, security program manager for Microsoft's security response team. "The guidance we are giving in general is to treat the critical ones first."

A single computer would not be vulnerable to all the flaws, Toulouse added.

Oliver Friedrichs, senior director of Symantec's security response center, said three vulnerabilities could lead to a Sasser-like worm, but the danger is lessened by the fact that the vulnerable services are not started by default on most versions of Windows. These flaws are related to three network protocols that are not generally activated on Windows computers: Simple Mail Transfer Protocol (SMTP), Network News Transfer Protocol (NNTP), and Network Dynamic Data Exchange (NetDDE).

"Blaster and Sasser targeted core system vulnerabilities, where if you didn't have the patch you were vulnerable," Friedrichs said. "The key thing here is that these are not (generally) enabled by default.The question is how large is the deployment of vulnerable systems."

Microsoft rates the SMTP flaw critical only for Microsoft Exchange Server 2003. The NNTP flaw is rated critical for Microsoft Exchange 2000.

The other major class of flaws are those that affect applications on desktop computers, such as Internet Explorer and Excel. Threats to so-called client-side applications have been growing, Friedrichs said.

Of the current crop of vulnerabilities, 12 fall into that category. Of these, Microsoft rated five critical: three of the eight vulnerabilities in Internet Explorer, as well as two flaws in Excel.

Several of the flaws could be used to create Web content that would run a program from the Internet, if a victim could be lured to the malicious Web site.

Symantec raised its overall Internet Threat Condition to 2 from 1, on account of the newly released vulnerabilities.

Microsoft has also re-released a patch from last month's graphics vulnerability, fixing a conflict with Windows XP Service Pack 2.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 100 Talkback(s)
Microsoft witch hunt
More of those with so much to say should read A. Rands Fountain head
Wally (Read the rest)
Posted by: wallypapke@... Posted on: 11/02/04 You are currently: a Guest | | Terms of Use
Enough is enough already!  htotten | 10/12/04
re: Enough is enough already!  bugmenotznet | 10/12/04
Just isn't their week, is it? (nt)  Yagotta B. Kidding | 10/12/04
actually, it is  eLurker | 10/12/04
Patches!?! We don't need not stinkin PATCHES!  Laff | 10/13/04
Yes, you do need patches if you're a Mac user  tic swayback | 10/13/04
True if you use MS products.  Laff | 10/14/04
MSFT Users: Assume The Position!  Chad_z | 10/12/04
I will gladly assume the position...  Confused by religion | 10/12/04
that 2 mins turns into longer than you think...  Monkey_MCSE | 10/12/04
What's the problem with a reboot?  d_jedi | 10/12/04
Problem with a reboot?  jasonp@... | 10/12/04
problem w/ reboot  coffeegurrl | 10/12/04
Hmm..  d_jedi | 10/13/04
Things that make you go...  The King's Servant | 10/14/04
plenty of problems rebooting  Monkey_MCSE | 10/12/04
Desktops and data  Yagotta B. Kidding | 10/12/04
yeah, thats where we are safe...  Monkey_MCSE | 10/12/04
You mean your users don't back their data up?  kribor_z | 10/12/04
backup - what a crappy paradigm  hipparchus2000 | 10/12/04
re:plenty of problems rebooting  richdave | 10/12/04
yes, well i came into the network  Monkey_MCSE | 10/12/04
Problem with a reboot?!?  Martin Marvinski | 10/13/04
Well...the truth on that  IT Scion | 10/13/04
outbound network connections  V Sanders | 10/12/04
Well..  d_jedi | 10/12/04
Still shouldn't need outbound connectivity  rpmyers1 | 10/12/04
...but it does, and sounds warning to Sysadmins  Jiim_z | 10/12/04
Microsoft warns of a score of security flaws  Loverock Davidson | 10/12/04
OK, let's  rpmyers1 | 10/12/04
Sorry  Loverock Davidson | 10/12/04
So you *don't* want to compare apples to apples (pun not intended)  rpmyers1 | 10/12/04
His point  SC-man | 10/13/04
Can't back up your claim? . . . Figures. (NT)  Plain Logic | 10/12/04
You are complaining about a developer release?  B.O.F.H. | 10/12/04
Since when is Fedora a beta?  d_jedi | 10/12/04
I personally don't care what you use!  B.O.F.H. | 10/12/04
More to the point  Yagotta B. Kidding | 10/12/04
remember, fedora is always updating...  Monkey_MCSE | 10/12/04
160 updates, but how many security flaws.  el1jones | 10/12/04
re:Microsoft warns of a score of security flaws  richdave | 10/12/04
he's actually a BSD user(NT)  Monkey_MCSE | 10/12/04
Linux updates  lloydv@... | 10/14/04
Every new WinXP machine I get is downgraded to Win2kSP1  The King's Servant | 10/14/04
Rep delivered the goods...  Mike Cox | 10/12/04
More like a dead animal under your house...  Expatriate US Geek | 10/12/04
So by pure butter  Linux User 147560 | 10/12/04
CD-ROM?  Michael Kelly | 10/12/04
"pure butter"  Yagotta B. Kidding | 10/12/04
pure butter  kribor_z | 10/12/04
7.8 . . . But shouldn't that be "pure vasoline"? . (NT)  Plain Logic | 10/12/04
Poor, poor Michael  SC-man | 10/13/04
You have to reply to Mike more often  The King's Servant | 10/14/04
(NT)10!!  toadlife | 10/15/04
5.5  nucrash | 10/13/04
who's who  pj-xmesh | 10/12/04
Thank goodness for automatic updates.  No_Ax_to_Grind | 10/12/04
Thank goodness for automatic updates.  AmusedAtItAll | 10/12/04
Re: Thank goodness for automatic updates.  rpmyers1 | 10/12/04
Re:Re: Thank goodness for automatic updates.  richdave | 10/12/04
Ditto  Martin Marvinski | 10/13/04
I use YUM evry night.  jpfitz@... | 10/13/04
Good point  voska | 10/12/04
Auto Updates (M$FT)  kribor_z | 10/12/04
How did you get off of Office?  Plain Logic | 10/12/04
Some place never used Office  voska | 10/12/04
It helps to be the CTO  kribor_z | 10/13/04
I'd rather get a virus  coffeegurrl | 10/12/04
And thank goodness for a whole industry created by flaws!  Xunil_Sierutuf | 10/12/04
Some might call that job security  voska | 10/12/04
Good for the clients, servers are a different story  doctormoriarty | 10/12/04
automtic updates - don't forget the reboot - lol  V Sanders | 10/12/04
Bitty, you never answered...  Martin Marvinski | 10/13/04
Mozilla Firefox  medical1 | 10/12/04
if only it were that simple  psychodave | 10/12/04
Mozilla has security holes too  IT Scion | 10/13/04
And your point is?  The King's Servant | 10/14/04
MS Crapmanship  michael-t | 10/12/04
Thank you MSFT for your efforts towards full employment...  Plain Logic | 10/12/04
Unfortunetly I support Mac's...I'm like the Maytag  Laff | 10/13/04
So true  Nullifidian | 10/13/04
Which flaw is NEW?  ESFabian | 10/12/04
anouther ie patch  V Sanders | 10/12/04
plus if a server does crash  V Sanders | 10/12/04
Microsoft warns of 22 new security flaws  stewart@... | 10/12/04
LongHorn  cashaww | 10/12/04
re:LongHorn  richdave | 10/12/04
I gave it to them...  jskline0@... | 10/14/04
MS wishes to have 22 other offences taken into consideration...  Tim Carpenter | 10/13/04
At some point, these flaws were automatically downloaded to all WIndows PCs  whisperycat | 10/13/04
No matter what this is BAD for MS. Take all the  Laff | 10/13/04
Better some help than none  SatelliteSteve | 10/13/04
22 Flaws? Is That All?  itanalyst | 10/13/04
Anyone Got A Patch Count?  itanalyst | 10/13/04
My cumputer does not boot now!  alokgovil | 10/13/04
It's secure now!  boomslang_z | 10/13/04
The ULTIMATE Windows Security Fix!  Joel R | 10/14/04
Microsoft Crustworthy Computing  boomslang_z | 10/14/04
Song of Praise for Microsoft ( parody)  DragonBRockin | 10/14/04
Microsoft witch hunt  wallypapke@... | 11/02/04

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

Meet Doc

  • Here to help you with your Document Management Needs
  • Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
  • To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
  • Produced by
    ZDNet and