Skip to main content

Microsoft Tackles Multiple Zero-Day Flaws


Microsoft has delivered its monthly Patch Tuesday update that includes fixes for the usual suspects such as Internet Explorer, Edge and Microsoft Office.





Redmond is also changing the way it delivers its security update with a new system designed to give system administrators more time to test the patches on their own systems.

Patch Tuesday

The latest Patch Tuesday from Microsoft delivers 10 bulletins that has a total of 36 unique CVEs (Common Vulnerabilities and Exposures).

Six of these bulletins are rated critical and a large number of zero-day flaws have been fixed, so system administrators will have a busy few days ahead.

This Patch Tuesday … definitely a step back from September’s massive list, but also not a light month by any measure,” blogged Karl Sigler, Threat Intelligence Manager at Trustwave. “Six of the bulletins are rated Critical and is mostly a list of our usual suspects, namely Internet Explorer, Edge, Graphics Component, Adobe Flash and the Microsoft Office suite.”

“The sixth Critical bulletin is in Windows Object Linking and Embedding (OLE),” wrote Sigler. “The vulnerability allows an attacker to execute arbitrary code in the context of the victim’s account by tricking the victim into opening a specific email or visiting a website.”

Microsoft has fixed zero day flaws with Internet Explorer and Edge with MS16-118 and MS16-118 respectively. MS16-121 resolves a vulnerability in Microsoft Office for an RTF remote code execution flaw. MS16-120 tackles a flaw with Microsoft Graphics Component.

MS16-127 addresses the vulnerabilities in Adobe Flash Player by updating the affected Flash libraries contained within both of Microsoft web browsers.

Researchers at Proofpoint meanwhile pointed out in a new blog post that Microsoft has patched a zero day vulnerability which was associated with the AdGholas malvertising campaign.

It seems that Proofpoint researchers Will Metcalf and Kafeine first detected AdGholas earlier this year, and they warned at the time that it had pulled in as many as one million client machines per day, and that it had been in operation since 2015.

“Threat actors, particularly those in the AdGholas and GooNky groups, continue to look for new means to exploit browser flaws,” blogged the Proofpoint researchers. “More importantly, though, they are turning to flaws that allow them to focus on ‘high-quality users’, specifically consumers rather than researchers, vendors, and sandbox environments that could detect their operations.”

Update Changes

Microsoft meanwhile has begun to change the way it delivers its Patch Tuesday update to help ease the burden on system administrators.

Microsoft’s new approach to patches will be based on a two-step method,” explained Amol Sarwate, director of Vulnerability Labs at Qualys. Firstly “Patch Tuesday … includes two main parts in itself; a security-only update and a security monthly rollup. Internet Explorer is included within this update.”

Second is “Third Tuesday …this is a monthly package of information of what to expect as a non-security fix in the next monthly rollup,” blogged Sarwate. “It details what the fixes were from the previous month to enable customers to test their systems before the next month.”

Comments

Popular posts from this blog

Security Alert; Bart Ransomware Bypasses Corporate Firewalls

A new ransomware variant has emerged that’s similar to widespread threats such as Dridex 220 and Locky Affid=3, but uses a security-evading technique that may allow it to attack organisations protected from other malware, according to computer security researchers. Ransomware has spread quickly in the last few months, as a number of payouts have attracted cyber-criminals to the technique.

BT And Nokia Strike 5G Research Deal

BT and Nokia have signed a research collaboration agreement together to work on next generation 5G technologies. Both companies say they went to work on finding potential customer use cases for emerging 5G networks, and will collaborate on proof of concept trials for 5G. “Nokia is delighted to be working with BT in laying the foundations for 5G adoption in the coming years, and in helping define how this technology will enable exciting and innovative experiences,” said Nokia UK head Cormac Whelan. Speed Nokia stand MWC 20165G networks should offer customers faster speeds and lower latency, and will become especially pertinent through the Internet of Things over the next decade. Commercial 5G networks will offer speeds of at least 1Gbps, and have 1,000 times more capacity than 4G networks. Such speeds would allow for the simultaneous streaming of data-heavy content such as virtual reality or live 360 degree video to any device, while greatly reduced latency would mean real-t...

Mourinho Officially Begins Work As United Manager Today

Jose Mourinho officially started work as Manchester United manager at the club's Carrington training base on Monday. The Portuguese travelled to Manchester by train on Sunday night and posted a video on Instagram showing his arrival at Picadilly station, saying: "I am here/UNITED we can". He arrived at Carrington with goalkeeping coach Silvino Louro on Monday morning.