Home > Enterprise Desktop News > Microsoft's August patches run the gamut
Enterprise Desktop News:
EMAIL THIS

Microsoft's August patches run the gamut

By Bridget Botelho, News Writer
11 Aug 2009 | SearchEnterpriseDesktop.com

News on enterprise Windows platforms and applications
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Microsoft Corp. released nine security updates on patch Tuesday that touch almost every Microsoft product in the enterprise, from servers to client systems, giving IT administrators plenty to worry about.

"This is one of the most widespread patch months Microsoft has ever done. The patches run the gamut and touch everything in the enterprise except for Internet Explorer," said Eric Schultze, CTO of St. Paul, Minn.-based patch management and security software company Shavlik Technologies LLC.

Schultze laid out the patches that IT administrators should put on the top of their priority list and said one of the most critical is the Internet Information Services (IIS7) Web server patch (MS09-036). It addresses a flaw that lets attackers send packets to your Web server that cause it to stop functioning (denial of service). IIS7 websites are safe if they are running in "classic" mode, but those running in integrated (non-classic) mode are vulnerable. The patch for this IIS7 issue is really a patch for .Net Framework versions 2 and 3, Schultze said.

"If you're running IIS7 [classic or otherwise], I'd recommend patching this one soon, unless you want your .asp and .aspx pages to stop functioning," he said.

Another critical patch that should be installed immediately is MS09-039, affecting WINS Servers. "Almost every Microsoft customer has a WINS server, so this is probably the most critical patch," Schultze said.

He said MS09-039 is a critical issue for WINS server part of the network infrastructure because without it, "attackers can point to the server with no permissions whatsoever and do whatever they want," he said. "They could create their own admin account without any permissions and execute code."

Microsoft also patched five different ActiveX controls, following one ActiveX fix last month and an out of band patchout-of-band patch the company issued a couple of weeks ago. This month's patches fix a related but different issue, where "evil websites could run code on your computer," Schultze said.

"If you think your users might visit any websites when they are bored, it's a good idea to issue the patch right away," he said.

And some other patches that should be high on IT administrators' priority list this month are MS09-040 and -041 addressing privilege escalation attacks. These flaws let anyone with user-level access to systems like print servers, file servers and domain controllers point packets to those systems and execute code, or read files with sensitive information, like payroll, Schultze said.

"This one really bothers me because it breaks down internal security controls," he said. "Patch this one while patching your WINS servers to keep idle internal miscreants from owning your machines."

Information on the other patches can be found on Microsoft's Security Bulletin website.

Let us know what you think about the story; email Bridget Botelho, News Writer



Tags: Patches, alerts and critical updatesMicrosoft Windows Vista operating systemMicrosoft Windows XP ProVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Patches, alerts and critical updates
Microsoft releases six patches for November
Structuring patch management in seven steps
Underlying causes of inconsistent patch management
Microsoft's Online Desktop Manager caters to small IT shops
Microsoft's Patch Tuesday brings a bumper crop of security fixes
Act fast with five critical September patches
Patching third-party browsers adds more work in Windows shops
Troubleshooting Microsoft WSUS connectivity issues
Windows security tools for the busy desktop administrator
The state of enterprise security and emerging threats in 2009

Microsoft Windows Vista operating system
Windows 7 launches, offers salvation from Vista
An intro to Windows 7's Deployment Image Servicing and Management tool
Guide to converting from Windows XP to Windows 7
Choosing the best way to install images
Has Microsoft corrected Vista annoyances in Windows 7?
Your questions answered: The Windows 7 upgrade quandary
Windows Vista users get little pricing relief on Windows 7
Combining folder redirection with roaming profiles
IPv6 protocol, Windows Vista features simplify peer ad-hoc networking
When to move off XP, onto Windows 7

Microsoft Windows XP Pro
Guide to converting from Windows XP to Windows 7
Top 5 registry keys for Windows XP
Manage the desktop image lifecycle to limit work, ensure security
Secure Windows XP before a Windows 7 upgrade
Hold on to Windows XP at your peril
XP stragglers blame hardware costs, new features
Your questions answered: The Windows 7 upgrade quandary
Windows Vista users get little pricing relief on Windows 7
Vista shops eye quick path to Windows 7, XP shops likely to resist
Google Chrome likely a niche player in Windows enterprise

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
drive-by download  (SearchEnterpriseDesktop.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Windows Desktop Technology - Virtualization, Virtual Infrastructure, Virtual Desktop
HomeTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogs
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts