Home > Enterprise Desktop News > Microsoft's August patches run the gamut
Enterprise Desktop News:
EMAIL THIS

Microsoft's August patches run the gamut

By Bridget Botelho, News Writer
11 Aug 2009 | SearchEnterpriseDesktop.com

News on enterprise Windows platforms and applications
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Microsoft Corp. released nine security updates on patch Tuesday that touch almost every Microsoft product in the enterprise, from servers to client systems, giving IT administrators plenty to worry about.

"This is one of the most widespread patch months Microsoft has ever done. The patches run the gamut and touch everything in the enterprise except for Internet Explorer," said Eric Schultze, CTO of St. Paul, Minn.-based patch management and security software company Shavlik Technologies LLC.

Schultze laid out the patches that IT administrators should put on the top of their priority list and said one of the most critical is the Internet Information Services (IIS7) Web server patch (MS09-036). It addresses a flaw that lets attackers send packets to your Web server that cause it to stop functioning (denial of service). IIS7 websites are safe if they are running in "classic" mode, but those running in integrated (non-classic) mode are vulnerable. The patch for this IIS7 issue is really a patch for .Net Framework versions 2 and 3, Schultze said.

"If you're running IIS7 [classic or otherwise], I'd recommend patching this one soon, unless you want your .asp and .aspx pages to stop functioning," he said.

Another critical patch that should be installed immediately is MS09-039, affecting WINS Servers. "Almost every Microsoft customer has a WINS server, so this is probably the most critical patch," Schultze said.

He said MS09-039 is a critical issue for WINS server part of the network infrastructure because without it, "attackers can point to the server with no permissions whatsoever and do whatever they want," he said. "They could create their own admin account without any permissions and execute code."

Microsoft also patched five different ActiveX controls, following one ActiveX fix last month and an out of band patchout-of-band patch the company issued a couple of weeks ago. This month's patches fix a related but different issue, where "evil websites could run code on your computer," Schultze said.

"If you think your users might visit any websites when they are bored, it's a good idea to issue the patch right away," he said.

And some other patches that should be high on IT administrators' priority list this month are MS09-040 and -041 addressing privilege escalation attacks. These flaws let anyone with user-level access to systems like print servers, file servers and domain controllers point packets to those systems and execute code, or read files with sensitive information, like payroll, Schultze said.

"This one really bothers me because it breaks down internal security controls," he said. "Patch this one while patching your WINS servers to keep idle internal miscreants from owning your machines."

Information on the other patches can be found on Microsoft's Security Bulletin website.

Let us know what you think about the story; email Bridget Botelho, News Writer



Tags: Patches, alerts and critical updatesMicrosoft Windows Vista operating systemMicrosoft Windows XP ProVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Patches, alerts and critical updates
Microsoft issues two Patch Tuesday bulletins, but omits one patch
February's Patch Tuesday brings an array of bulletins
Securing removable drives with BitLocker To Go
Patch management guide for Windows desktops
New year begins with a light Patch Tuesday
Desktop security predictions for 2010
Top 10 Windows desktop security tips of 2009
Microsoft beats the holiday rush, releases patches for IE and Windows
Microsoft releases six patches for November
Structuring patch management in seven steps

Microsoft Windows Vista operating system
No legacy Windows support, no problem for some IT managers
XP, Vista or Windows 7: Which is the most secure desktop OS?
User State Migration Tool: A step-by-step guide
Best third-party tools for desktop management
What USMT will and won't do
More USMT installation steps
Migrating from XP to Windows 7 with the User State Migration Tool
Checklist for upgrading from Windows XP or Vista to Windows 7
Windows 7 launches, offers salvation from Vista
An intro to Windows 7's Deployment Image Servicing and Management tool

Microsoft Windows XP Pro
Planning a migration from Windows XP to Windows 7
No legacy Windows support, no problem for some IT managers
XP, Vista or Windows 7: Which is the most secure desktop OS?
User State Migration Tool: A step-by-step guide
Best third-party tools for desktop management
What USMT will and won't do
More USMT installation steps
Migrating from XP to Windows 7 with the User State Migration Tool
Steps for solving the reboot loop problem
Checklist for upgrading from Windows XP or Vista to Windows 7

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
drive-by download  (SearchEnterpriseDesktop.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Windows Desktop Technology - Virtualization, Virtual Infrastructure, Virtual Desktop
HomeTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogs
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts