Internet Explorer, Office Hit Hard on Patch Tuesday
Microsoft's 11 patches heavy on client side.
"Some of these can get nasty if left unpatched," says Jason Miller, security data team manager for Shavlik Technologies.
Miller says in addition to the Internet Explorer vulnerabilities, he would highlight those in MS08-046, which addresses flaws in the Windows Image Color Management System.
"I fully expect in the next couple of weeks, if not already, we will start to see these specialty crafted evil Web sites out there," Miller says. "With the imaging part, it could be used in inline advertising." Miller says a user can be compromised just by pulling up the Web site.
He also notes that the August security patches were a load. "If you are patching a corporate network, this is quite a lot to get your arms around," he says.
The other patch that corporate users should be concerned with is MS08-047, which addresses a vulnerability in IPsec.
"There are ways that people can build exploits that would turn an IPsec session into an open text session," Lumension's Leatham says. He says healthcare and financial services companies could classify 047 as critical given that data thought to be secure could be passed as clear text, posing a significant security risk.
Microsoft says an attacker viewing the traffic on the network might possibly be able to modify the contents of the traffic in the IPsec session. The attack would require sniffing network traffic and therefore is more likely to be carried out by an internal hacker. The 047 patch covers Vista and Windows Server 2008.
"Vista and Server 2008, which are supposed to be on the forefront of computer security, are still having security issues and patches. So being on those platforms does not mean you are more secure than being on XP and Server 2003," Shavlik's Miller says.
The patches come on top of security advisories issues last month, especially one around DNS spoofing, which is not reportedly being exploited in the wild. Security experts say corporate users should have the patch high on their list if they have not already installed it.
Microsoft



