Microsoft warns of 22 new security flaws

By Robert Lemos, Special to ZDNet
13 October 2004 08:28 AM
Tags: netdde, excel, nt, ms, european union, mac, flaw, windows
Microsoft on Tuesday published 10 software security advisories, warning Windows users and corporate administrators of 22 new flaws that affect the company's products.

The advisories, and patches published with the bulletins, range from an "important" flaw affecting only Microsoft Windows NT Server to a collection of eight security holes, including three rated "critical," that leave Internet Explorer open to attack. Microsoft's highest severity rating for software flaws is its "critical" ranking, while "important" is considered slightly less severe.

One flaw, in Microsoft Excel, even affects Apple Computer's Mac OS X.

The abundance of flaws could leave corporate PCs vulnerable to attack if administrators are not able to patch quickly. A similar situation occurred in April, when Microsoft published seven advisories detailing 20 flaws. While one security hole stood out among those 20--and led to the widespread Sasser worm--there are no standouts in the current gaggle of goofs.

"Our challenge is trying to guess what the criminals are going to attack," said Stephen Toulouse, security program manager for Microsoft's security response team. "The guidance we are giving in general is to treat the critical ones first."

A single computer would not be vulnerable to all the flaws, Toulouse added.

Oliver Friedrichs, senior director of Symantec's security response center, said three vulnerabilities could lead to a Sasser-like worm, but the danger is lessened by the fact that the vulnerable services are not started by default on most versions of Windows. These flaws are related to three network protocols that are not generally activated on Windows computers: Simple Mail Transfer Protocol (SMTP), Network News Transfer Protocol (NNTP), and Network Dynamic Data Exchange (NetDDE).

"Blaster and Sasser targeted core system vulnerabilities, where if you didn't have the patch you were vulnerable," Friedrichs said. "The key thing here is that these are not (generally) enabled by default.The question is how large is the deployment of vulnerable systems."

Microsoft rates the SMTP flaw critical only for Microsoft Exchange Server 2003. The NNTP flaw is rated critical for Microsoft Exchange 2000.

The other major class of flaws are those that affect applications on desktop computers, such as Internet Explorer and Excel. Threats to so-called client-side applications have been growing, Friedrichs said.

Of the current crop of vulnerabilities, 12 fall into that category. Of these, Microsoft rated five critical: three of the eight vulnerabilities in Internet Explorer, as well as two flaws in Excel.

Several of the flaws could be used to create Web content that would run a program from the Internet, if a victim could be lured to the malicious Web site.

Symantec raised its overall Internet Threat Condition to 2 from 1, on account of the newly released vulnerabilities.

Microsoft has also re-released a patch from last month's graphics vulnerability, fixing a conflict with Windows XP Service Pack 2.

Advertisement

Talkback 4 comments

    Commonsense now demands a reth ...Anonymous -- 13/10/04

    Commonsense now demands a rethink on the part of microsoft and others.

    The simple answer is to reduce the number of ports available for communication in computers and register all uses of ports.

    Computing is becomming far to complex for most people, and they are beyond caring, often choosing to ignore it.

    So how do the IT pro's cope?

    According to what I read it is determined often by the business focus and budget.

    hence why something drastuic needs to be done to reduce the the width of the playing field.

    It is amazing how most compani ...Anonymous -- 13/10/04

    It is amazing how most companies are reluctant to switch to Linux because of the cost of retraining their IT staff, but are happy to have their Windows systems constantly exposed and compromised by trojans and worms.

    Hugh, have you actually done t ...Anonymous -- 13/10/04

    Hugh, have you actually done the numbers to see how much it costs to re-train NT admins to go to Win2k3? It's about the same as re-training them to go to Linux. Most firms therefore cannot use this as an excuse for not migrating to Linux.

    Recent reports seem to indicat ...Anonymous -- 13/10/04

    Recent reports seem to indicate that there's not much difference in the number of vulnerabilities between Windows & Linux - Linux has slightly more, Windows has a higher % critical vulnerabilities but they fix them faster than the Linux crew. On average they're as bad as each other.
    Given that, there's no reason to move to Linux based on vulnerabilities. On the other hand, my guess is there's less ego to be gained from taking advantage of Linux vulnerabilities, making it the slightly better option.
    Providing you can justify the migration costs, of course.

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Love me, tender
    Considering how expensive and drawn-out tender processes can be to solve problems that might be very immediate, it's little wonder that the Victorian Police IT department tried to work the tender exemptions system.
  • Array 2009 funding drought rolls on
    For Australian start-ups looking for venture capital, 2009 was a very bad year. 2010 may be no better.
  • Array Can not-so-smart meters help the NBN?
    It was interesting to witness Conroy's recent enthusiasm to spruik the NBN's role in supporting the Smart Grid, Smart City initiative. What a pity that Conroy hadn't yet seen the damning report from the Victorian auditor-general about that state's smart-meter roll-out.
  • More blogs »

Tags

Back to top

Featured