two
Volume 4, Number 34 -- September 12, 2007

Microsoft Patches Four Security Flaws

Published: September 12, 2007

by Alex Woodie

Microsoft yesterday issued four patches fixing four security flaws affecting several of its products, including two flaws affecting recent versions of Windows, and three that have been publicly disclosed. There was only a single critical flaw issued yesterday--for a remote code execution vulnerability affecting Windows 2000 SP4--and three other patches the company deemed "important." A fifth patch was in the works as recently as Friday, but the software giant elected against releasing it for its September Patch Tuesday.

The critical patch, as delivered by Microsoft Security Bulletin MS07-051, fixes a serious problem in the Microsoft Agent software in Windows 2000 SP4 that could allow an attacker to take complete control of an affected system if the user visited a malformed Web site or opened a malicious e-mail.

The vulnerability is a variation on the Microsoft Agent URL Parsing Vulnerability that Microsoft fixed in July for all Windows operating systems. Apparently, that patch didn't entirely fix things for Windows 2000 SP4 users. But nobody has been hurt yet, as Microsoft says the vulnerability has not been publicly disclosed, nor used as the basis for an attack. Just the same, Windows 2000 SP4 users should apply the patch immediately, as hackers and script kiddies are bound to start using the flaw for attempted exploits in the days and weeks to come.

Windows developers who use the version of Visual Studio that contains an integrated version of Crystal Reports should apply Microsoft Security Bulletin MS07-052 immediately. This patch fixes a known remote code execution flaw in Visual Studio that can be exploited by opening malicious RPT files. This flaw, which is also known as the Crystal Reports Stack Overflow Vulnerability, has been publicly reported for some time. Nevertheless, Microsoft says it's not aware of any successful attacks utilizing this vulnerability.

Microsoft Security Bulletin MS07-053 fixes an important vulnerability in all modern versions of Windows, including Windows 2000, Windows XP, Windows Server 2003, and Windows Vista. The problem has to do with the Windows Services for Unix and the Subsystem for Unix-based Applications components in Windows—specifically the "setuid" routine, which is used to run programs under the program's owner's user profile instead of the user profile of the user making the request. Microsoft credits Brian Reiter of WolfeReiter with finding and reporting the flaw, which Microsoft says has been publicly disclosed, and is in limited distribution.

The final fix, Microsoft Security Bulletin MS07-054, may be the most important. MS07-54 addresses an "important" vulnerability in MSN Messenger versions 6.2, 7, 7.5, and 8.0 that could allow an attacker to take complete control of an affected system if the user accepted a malicious chat request.

While Microsoft has since shipped MSN 8.1, which is not susceptible to the problem--which is officially known as the MSN Messenger Webcam or Video Chat Session Remote Code Execution Vulnerability--the older versions of MSN Messenger were shipped on almost all versions of Windows, including Windows Server 2003 and Windows Vista. The fact that this vulnerability has been publicly reported--credit for finding it goes to Woo Shi of team 509--makes it even more dangerous.

Microsoft did not give this vulnerability a critical rating, despite the fact that it carries a remote code execution risk, because it requires some trickery on the part of the hacker to get the user to accept the malicious chat request. However, this is the same level of user stupidity required to make the Microsoft Agent URL Parsing Vulnerability work, and this vuln received the "critical" rating.

Also making MS07-54 stand out is the fact that it's the latest in a string of vulnerabilities to target social networking sites and their supporting technologies. According to security tool vendor Qualys, a range of other vendors have addressed problems in the technology supporting social networking sites, including Adobe, Real Networks, and Apple. Apparently, hackers are turning their attentions to social networking sites as they become more popular.

Microsoft also pulled a patch for its SharePoint software at the last second. When Microsoft sent out its usual e-mail last Thursday telling customers what patches to expect on Patch Tuesday, it had five patches, including one for an elevation of privilege risk for SharePoint. Microsoft did not disclose why it chose not to ship this patch, although it was almost certainly a quality issue.




                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
STORAGE GUARDIAN

For a limited, Storage Guardian is offering
our remote backup services at a rate of
$8/compressed GB/month (based on a
3:1 compression ratio) with
No Minimum GB/month Commitment.

                                            · Backup System State / Active Directory
                                            · SQL, MS Exchange, .PST files "Open & Locked"
                                            · Bare Metal Restore

Get your estimate NOW at:
www.storageguardian.com


Editor: Alex Woodie
Contributing Editors: Dan Burger, Joe Hertvik,
Shannon O'Donnell, Timothy Prickett Morgan
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

COMMON:  Join us at the annual 2008 conference, March 30 - April 3, in Nashville, Tennessee
World Data Products:  Free Server Spec Book for the design, installation and maintenance of servers
NowWhatJobs.net:  NowWhatJobs.net is the resource for job transitions after age 40

 

 

IT Jungle Store Top Book Picks

The System i Pocket RPG & RPG IV Guide: List Price, $69.95
The iSeries Pocket Database Guide: List Price, $59.00
The iSeries Pocket Developers' Guide: List Price, $59.00
The iSeries Pocket SQL Guide: List Price, $59.00
The iSeries Pocket Query Guide: List Price, $49.00
The iSeries Pocket WebFacing Primer: List Price, $39.00
Migrating to WebSphere Express for iSeries: List Price, $49.00
iSeries Express Web Implementer's Guide: List Price, $59.00
Getting Started with WebSphere Development Studio for iSeries: List Price, $79.95
Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
Getting Started with WebSphere Express for iSeries: List Price, $49.00
WebFacing Application Design and Development Guide: List Price, $55.00
Can the AS/400 Survive IBM?: List Price, $49.00
The All-Everything Machine: List Price, $29.95
Chip Wars: List Price, $29.95


 
The Four Hundred
Supermegavirtualizationfest 2007

Reader Feedback on the Death of DB2/400 for Domino

Sirius Expands Northeast Presence with SCS Buy

As I See It: The Dons of Dialogue

The Linux Beacon
AMD Gets Aggressive About Watts with Quad-Core Barcelonas

NASA Buys Big Xeon-Linux Cluster from SGI

VMware Trims Down Hypervisor for Embedding in Servers

XenSource Offers Embedded Hypervisor for Servers

Four Hundred Stuff
Sentillion Aims for Low Cost, Ease-of-Use with SSO Product

Vaulting Over Backups: The Pros, Cons

Bsafe Puts a Smack Down on Rouge IP Traffic

Raz-Lee Eases Compliance with Update to iSecurity

Big Iron
PSI Adopts NEC Itanium Servers for Mainframe Clones

Top Mainframe Stories From Around the Web

Chats, Webinars, Seminars, Shows, and Other Happenings

Four Hundred Guru
PHP: An Easy Yet Powerful Language Syntax

I Want My F15 Back!

Admin Alert: Magical & Mysterious iSeries Access CWB Programs

System i PTF Guide
August 11, 2007: Volume 9, Number 32

August 4, 2007: Volume 9, Number 31

July 28, 2007: Volume 9, Number 30

July 21, 2007: Volume 9, Number 29

July 14, 2007: Volume 9, Number 28

July 7, 2007: Volume 9, Number 27

The Unix Guardian
The Left and Right Hands of Sun

Core Transition Complete as Intel Ships 'Tigerton' Xeon MPs

NetApp Sues Sun Over File System Patents

Mad Dog 21/21: Leverage

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

THIS ISSUE SPONSORED BY:

IT Security
Vibrant Technologies
Lakeview Technology
Storage Guardian
MKS


Printer Friendly Version


TABLE OF CONTENTS
New Test Releases of Windows Server 2008, 'Viridian' Imminent

AMD Gets Aggressive About Watts with Quad-Core Barcelonas

Microsoft Ships BizTalk Server R2

Microsoft Patches Four Security Flaws

But Wait, There's More:

Microsoft Updates Edge Security Products . . . Sentillion Aims for Low Cost, Ease-of-Use with SSO Product . . . VMware Trims Down Hypervisor for Embedding in Servers . . . XenSource Offers Embedded Hypervisor for Servers . . . Core Transition Complete as Intel Ships 'Tigerton' Xeon MPs . . . Microsoft Looks to Improve on Daylight Savings Time Shift . . .

The Windows Observer

BACK ISSUES





 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2008 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement