Microsoft Fixes 11 Vulnerabilities
The six security updates Microsoft released on Tuesday patch a total of 11 bugs, five of which were rated critical, across Windows, Office and the .NET Framework.
That last, although rated "moderate," second from the bottom in Microsoft's four-step severity rating system, is worth some reflection, said Symantec's Friedrichs.
"Microsoft's decision to rewrite the Windows network stack and its accompanying firewall [for Vista] continues to have long-term security implications," Friedrichs said. "A network stack can take decades of heavy scrutiny in order to become battle hardened. As an operating system's first line of defense, its quality is directly related to its ability to withstand attack."
On its own, added Friedrichs, the firewall bug isn't a big deal; the result of an exploit is that the attacker can "see" the system when it should actually be completely invisible to outside probes. "[But] if this logic flaw were combined with a vulnerability in one of the exposed services, this could have more serious, widespread implications."
As usual, Microsoft's monthly updates have been posted to Microsoft Update and Windows Update services, and they can also be retrieved through Windows Server Update Services.
Microsoft



