Enterprise Newsletter
 
NEWSLETTERS
 

CIO.com updates, insights and advice on technology, management and your career.

 
 
 
LEADERSHIP
 
CIO Executive Programs
The Leader in Face-to-Face Education for Senior Executives

Offering regional and national programs, CIO (and CSO) events bring together some of the most respected names and thought leaders in information technology and security. Presented by CIOs and other senior level executives, these invitation-only programs offer timely topics and strong networking. Learn More »

 
CIO Executive Council
A Peer-Advisory Service and Professional Association for CIOs

Turn Geeks into Leaders

June 17, 11:30 AM - 12:30 PM U.S./ET (GMT-4)

Larry Bonfante, CIO of the U.S. Tennis Association, will discuss the skills and approaches that your rising IT leaders must learn to be effective in an executive capacity.

How to Handle Your New CEO: Managing Turnover at the Top

June 18, 11:00 AM - 12:00 PM U.S./Eastern (GMT-4)

Turbulent times have increased turnover at the top. Find out what Council CIOs have done to "break in" new CEOs—build relationships, set expectations, educate on the role of IT.

Mid-Market CIO Panel: Tips and Techniques for Improving Vendor Relationships

July 15, 4:00 PM - 5:00 PM U.S./Eastern (GMT-4)

We'll highlight relationship priorities and best practices identified in a Council study, and we'll interact with a CIO panel on the approaches they've used to improve strategic vendor partnerships.

Executive Competencies Assessment Tool

Assess Your Business Leadership Skills with the Council's new benchmarking tool. Rate yourself in change leadership, strategy, customer focus and more.

More / Register »

Learn more about the CIO Executive Council »



 
 
RESOURCE CENTER
 
 
 
SUBSCRIBE TO CIO
 
Are you involved in setting the direction for your company's IT budget or strategy?

Apply today for a FREE subscription to CIO Magazine!

 
 
 

Microsoft Fixes IE, DirectX Security Bugs

Microsoft has released security patches for some of its products, fixing critical flaws in the Internet Explorer browser, DirectX and Bluetooth wireless software for Windows.

 

June 10, 2008 — IDG News Service —

Microsoft has released security patches for some of its products, fixing critical flaws in the Internet Explorer browser, DirectX and Bluetooth wireless software for Windows.

The company has also released less-critical updates for its server products, fixing bugs in Active Directory, the Windows Internet Name Service (WINS) and the Pragmatic General Multicast (PGM) protocol, used by Windows to stream media to many recipients.

A seventh update, rated moderate, adds "kill bits" that disable buggy speech-recognition software and a program used to manage Logitech devices.

In total, 10 bugs were squashed in these seven updates, released Tuesday.

Desktop users will want to be sure to install the critical Internet Explorer and DirectX updates as soon as possible, said Amol Sarwate, vulnerability lab manager with security vendor Qualys. Some of the flaws addressed in these patches can be exploited in Web-based attacks where a criminal tricks the victim into visiting a malicious Web page and then takes advantage of the bug to install malicious software on the Windows PC.

The Bluetooth vulnerability is also rated critical by Microsoft. But to exploit this flaw, attackers would have to be close enough to the Windows machine to send it maliciously encoded Bluetooth packets, Sarwate said.

One of the two bugs that was patched in the MS08-031 Internet Explorer update has been publicly known since January. Attackers could take advantage of this flaw to get unauthorized access to data stored by the browser, Microsoft said.

Another publicly disclosed bug lies in the Microsoft Speech API, which lets Windows users operate their computers using voice commands. Last year, researchers discovered that they could do things like delete files on computers that used this technology, enabled by remotely playing voice commands on a victim's computer.

The Speech API flaw was one of two programs that Microsoft has disabled with its MS08-032 "kill bit" update. The second flaw lies in an ActiveX control that ships with the Logitech Desktop Manager (LDM) software.

The LDM, which manages Logitech devices like Web cameras, contains buggy software called the BackWeb Web Package ActiveX object. So if a victim running the LDM software visited a malicious Web site, attackers could theoretically take advantage of this flaw and run unauthorized software on his computer.

Third-party applications such as the Logitech Desktop Manager have been the source of many security problems for Windows users. Lately, researchers have discovered a rash of major flaws in products such as Apple's QuickTime, Adobe's Flash and other media players. Often, these bugs can be exploited by attackers in Web-based attacks in order to run unauthorized software on a victim's PC.

Copyright © 2008 IDG News Service. All rights reserved. IDG News Service is a trademark of International Data Group, Inc.
 
 
Loading...
 
WHITE PAPERS

Investing in Business Analytics Technology

Find the answers to your questions about business anyalytics initiatives.
 

Document-Sharing Solutions

Examine the benefits and challenges that IT executives are facing and how they plan to control the changes.
 

How Can Your Organization Weather This Economic Storm?

IT executives are under intense pressure to cut costs, and that pressure is significantly increased by the current grim economic outlook.
 

Deliver Higher-Performing Technology Services with ITIL

Enable the business and your IT organization to cope with the effects of economic stress.
 

Making Data Center Infrastructures More Adaptive

Learn how administrators can tackle problems in ways that were previously impossible.
 

Server Management Tools Automate Capabilities and Improve Efficiency

In this white paper, Info-Tech covers the key considerations of server management tools to take the pain out of day-to-day provisioning, patching and operational support.
 

WEBCASTS

Webcast with Dan Vesset: Investing in Business Analytics Technology

What exactly is business analytics and why should you care? Dan Vesset of IDC and Gaurav Verma of SAS answer this a...
 

Enterprise Cloud Computing: Ready for Primetime?

The progression toward enterprise cloud computing is happening today, as industry leaders deploy technologies that ...
 

Preparing Your Business Services for the Future

Would you trust your network monitoring tools enough to know when something is truly halting a business service? Wh...
 

Enterprise System Management Challenges in Big Organizations with Eli Almog

In this Podcast with Eli Almog, Corporate Architect in BMC's CTO Office, discusses how IT managers can know when it...
 

A Down-to-Earth look at Cloud Computing

Is cloud computing going to take over the data center as we know it? Join us as we talk about cloud computing with...
 

BSM in the Field, Practical Insights from Peter Armaly

Have you thought about BSM, but haven't quite gotten the buy-in you need? Get down and dirty with BSM installations...
 

Resource Alerts

Get instant email notifications by topic when white papers, webcasts, and case studies are added to our library.

 
FEATURED SPONSORS
 
 
 
SPONSORED LINKS
 

Seven Ways ITIL Can Help You in an Economic Downturn

Maximizing the Business Value of the PC Infrastructure

Using Open Source to Deploy Web Applications

How Interactive Viewer Reduces the Effort to Meet Visualization Requirements

White Paper: 8 Key Ingredients to Building an Internal Cloud

Software Executives: Take Control of Your Organization's Code Quality

BPM ROI calculator

Oracle's Application Grid Technical Demo

Next-Generation Application Servers and Infrastructure

Application Infrastructure at Enterprise Organizations

Achieving Business Agility with Application Grid

Craft a Strategy to Lower Your Total Cost of Ownership

A Natural User Interface for Enterprise Applications

On-Demand HR for a Global Organization

Four steps to populate your CMDB.

Delivering Secure and Reliable Data through Spreadsheet Automation

Open Source BI: Inexpensive Solutions for Developers

Gartner Shares Predictions for 2009

Get Google Enterprise Search for your business information.

Accenture IT Consulting: Enabling high performance. More...

Top Five CIO Challenges

Insight makes it easy to spend your Microsoft subsidy check.

Five minute business analytics assessment. Immediate results.

Dangerous Collaboration Practices: 5 Ways IT Can Minimize Risk

Accenture: Outsourcing for uncertain times. Click to learn more.

Revolutionizing Enterprise Application Deployment

Learn how to managing client systems in the enterprise.

Cloud Computing: Read about VMware's compelling vision & set of products

Top-line Performance that's Bottom-line Efficient

How Open Source is Changing the Face of Enterprise Software

BPM Survey Results: The Real-World Analysis

Ready to Act: 3 Recommendations for Agile Processes

Oracle WebLogic Server Technical Demo

Data Grids and Service-Oriented Architecture

Achieving the Impossible: Unlimited Application Scalability

A Middleware Foundation for Application Grid

Next Generation Enterprise Applications

A Truly Global HCM System

Learn how to provide complete Business Service Management.

Increase ROI of Your Application Portfolio

Financial Institutions Need Rich Internet Applicatons

Forrester: Implementing Rich Internet Applications

"Enterprise-Proven" is the Prerequisite for Enterprise SaaS Portal Solutions

Introducing the new HP ProLiant G6 server family

Accenture: Outsourcing for Competitive Advantage. More...

Better spam protection with Postini for just $1/user/mo

Introducing the new HP ProLiant G6 server family

infoBOOM! - The Mid-Sized Company CIO's Exclusive Community

Accenture IT Consulting: Logical meets technological. More . . .

The Fraudster Economy Model: Operating a Business in the Underground