Home > Security News > Inside MSRC: Microsoft addresses XML Core Services flaw, RPC flaw
Security News:
EMAIL THIS
COLUMN

Inside MSRC: Microsoft addresses XML Core Services flaw, RPC flaw

By Bill Sisk
11 Nov 2008 | SearchSecurity.com


Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Wow, November is upon us already! Time flies when you are having fun and working hard. With that in mind, I hope I can make life easier for you by extracting some of the salient information from this month's security bulletins.

Microsoft XML Core Services are included in several Microsoft products and more than one version can be installed on a single system.
Bill Sisk,
esponse communication manager, Microsoft Security Response Center (MSRC)

Our release is comprised of two bulletins this month, but first let me cover the out-of-band release that took place after October's regularly scheduled bulletin release.

October out-of-band release

MS08-067
Through internal sensors we discovered a limited number of exploit attempts that targeted a previously unknown vulnerability affecting all supported versions of Windows. As a result, we immediately initiated our Software Security Incident Response Process and started developing and testing a security update. On October 23, we released MS08-067 as an out-of-band security update to protect our customers.

In particular, this update addressed a vulnerability in the server service that could allow remote code execution. It is possible that this vulnerability could be used in the crafting of a wormable exploit on Microsoft Windows 2000, Windows XP and Windows Server 2003 systems. On Windows Vista and Windows Server 2008 machines, however, the vulnerability could only be exploited by an authenticated user, due to changes introduced by User Account Control (UAC).

About Inside MSRC:
As part of a special partnership with SearchSecurity.com, Bill Sisk, the response communication manager for the Microsoft Security Response Center (MSRC), offers an inside look at the process that leads up to "Patch Tuesday" and guidance to help security professionals make the most out of the software giant's security updates.

Also see:

Inside MSRC: Microsoft issues advice for critical server flaws

Inside MSRC: Microsoft provides guidance on GDI flaws

Inside MSRC: Microsoft issues guidance on DNS server update

As we continued monitoring the threat landscape after the release of the update, we found that the detailed exploit code for the vulnerability had been published on the Internet. This exploit code demonstrated code execution on Windows 2000, Windows XP and Windows Server 2003. We then issued an advisory to alert customers that the threat landscape had changed and reminded them of the prescriptive guidance provided in MS08-067. At the heart of this guidance, we encouraged customers to deploy the security update as soon as possible.

November Bulletin Release

MS08-068
This bulletin addresses a remote code execution vulnerability in Server Message Block (SMB). SMB mishandles NTLM credentials when a user attempts to authenticate to an attacker's SMB server. To mitigate possible exploit of this vulnerability, block TCP ports 139 and 445 at the firewall. Windows Vista and Windows 2008 are only rated as "moderate" in this bulletin, whereas Windows 2000, Windows XP and Windows Server 2003 are rated as "important."

MS08-069
There are three vulnerabilities in MSXML Core Services being addressed in this bulletin. The cumulative rating is "critical." However, only Microsoft XML Core Services 3.0 has this rating. Microsoft XML Core Services 4.0, Microsoft XML Core Services 5.0 and Microsoft XML Core Services 6.0 are rated as "important." Microsoft XML Core Services are included in several Microsoft products and more than one version can be installed on a single system. The bulletin provides detailed guidance and will save you time in your deployment strategies.

Last month I also covered the debut of the Microsoft Exploitability Index. I want to highlight it again.

The Exploitability Index provides additional information to help prioritize the deployment of monthly security bulletins. This index is designed to provide guidance on the likelihood of functional exploits, based on the vulnerabilities addressed by Microsoft security bulletins.

To help you better understand how it works, my colleague, Christopher Budd, wrote an excellent article entitled, Understanding How to Use the Microsoft Security Response Center Exploitability Index. I encourage you to review the article and integrate it into your risk assessment methodology.

In closing, please take a moment and register for our monthly security bulletin webcast, which will be held on Wednesday, Nov. 12 at 2 p.m. EDT.

Christopher Budd and Adrian Stone will review information about each bulletin to further aid in your planning and deployment. Immediately following the review session, they will answer your questions with information from our assembled panel of experts. If you are not able to view the live webcast, it will also be available on-demand.

In addition, please take a moment and mark your calendars for the December 2008 monthly bulletin. The release is scheduled for Tuesday December 9 and the advance notification is scheduled for Thursday, December 4. Look for the December edition of this column on release day for information to help you plan and deploy the most recent security bulletins.



Tags: Security Patch ManagementWindows Security: Alerts, Updates and Best PracticesSecuring Productivity ApplicationsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Security Patch Management
Squad: Tokenization, Phishing and the Feds
Should management processes change based on a patch release schedule?
Should Windows Mobile updates come from Microsoft?
Adobe updates ColdFusion, JRun, Flex
Trusteer CEO criticizes Adobe, touts better patch deployments
Patch management study shows IT taking significant risks
Vulnerability mitigation study shows need for faster patching
Microsoft to issue security report card, new tool at Black Hat
How to manage patches for Adobe
When is it suitable to remove Java updates?

Windows Security: Alerts, Updates and Best Practices
Windows 7 DoS flaw allows hackers to freeze Microsoft's newest OS
Microsoft patches serious Windows kernel flaws
Microsoft to address flaws in Windows, Office for Mac
Microsoft fixes security update that breaks Internet Explorer
What is the best database patch management process?
Microsoft addresses critical SMBv2 flaw, fixes record number of flaws
Microsoft to address SMB zero-day, IIS FTP Service vulnerabilities
Microsoft releases temporary fix for SMB2 zero-day vulnerability
Microsoft issues SMB vulnerability advisory, patch pending
Attackers target Microsoft IIS; new SMB flaw discovered

Securing Productivity Applications
Quiz: How to build secure applications
How to detect software tampering
Adobe fixes 29 flaws in Acrobat, Reader
Adobe warns of critical update for Reader, Acrobat 9.1.3
Why should we place data files on a separate partition than the OS?
Adobe updates ColdFusion, JRun, Flex
Serious Adobe Flash flaw being exploited
Adobe acknowledges serious Flash zero-day vulnerability
Adobe issues security advisory for Flash zero-day flaw
When to use the service features of the Metasploit hacking tool

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
attack vector  (SearchSecurity.com)
back door  (SearchSecurity.com)
ethical worm  (SearchSecurity.com)
Patch Tuesday  (SearchSecurity.com)
zero-day exploit  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts