Windows users: Patch now or turn off Bluetooth

Microsoft's June Patch Tuesday release included a critical fix affecting all Windows Vista and XP systems, which could allow attackers to wirelessly steal confidential information from laptops by exploiting a flaw in the Bluetooth stack.

The Bluetooth stack flaw, detailed in Microsoft bulletin CVE-2008-1453 and rated 'critical', could allow an attacker to take complete control of an affected system, install programs, alter data or create new accounts with full user rights.

The MS08-030 patch modifies the way that the Bluetooth stack handles a large number of service description requests.

Microsoft recommends applying the patch immediately and security experts advise users to turn off Bluetooth features until the patch has been applied.

Matthew Aburn, director of security consultancy Halcyon, said the flaw was particularly dangerous because hardware manufacturers usually set the factory default for Bluetooth as 'active'.

"Hardware-wise, most ship with Bluetooth on by default. I'd definitely recommended that if you're not using Bluetooth, you should turn it off," Aburn told ZDNet.com.au.

Rob Pregnall, Symantec's senior manager of Technical Product Management for Endpoint Security in Asia Pacific and Japan, agreed. He said that hardware manufacturers do this in order to make those features easier to access.

"When I look at a freshly bought machine from a reputable manufacturer, the first thing I notice is that every bell and whistle is turned on. I see it across different hardware manufacturers, including Macs," he said.

"All the different communication technologies are generally activated, so I think it's a move by manufacturers to ensure that everything is turned on so that minimal effort is needed to use the capabilities that users were sold on," Pregnall told ZDNet.com.au.

In a blog, Microsoft admits that although in most cases an attacker would need to be in close range to exploit the vulnerability, there are ways to increase that distance.

"The standard range of Bluetooth is in the order of meters, although an attacker could use specialised antennas to increase this," the blog said.

This was back up by Halcyon's Aburn.

"People look at the standard specifications for Bluetooth range of connectivity, which says you need to be so many metres away but using a directional antenna, people can target you from much further away," he said.

This month's Patch Tuesday also includes fixes for a drive by download weakness in Internet Explorer, as well as flaws in affecting Microsoft' multimedia APIs.

The critical vulnerability affecting Internet Explorer described in CVE-2008-1442 and CVE-2008-1544 only affects Windows XP and Vista systems. The MS08-031 cumulative patch fixes a couple of vulnerabilities, including one that could allow remote code execution if a user viewed a specially crafted Web page using Internet Explorer and another which could allow information disclosure if a similarly configured page was viewed using the browser.

The DirectX flaws affects all supported editions of Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008. This update addresses the vulnerability detailed in CVE-2008-0011 and CVE-2008-1444. Microsoft says the vulnerability "could allow remote code execution if a user opens a specially crafted media file. An attacker who successfully exploited either of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights."

Moderate and important updates
The one moderate bulletin covers a flaw in the speech recognition feature in Windows 2000, XP, and Windows Vista. Of the important bulletins, one concerns Active Directory and another Pragmatic General Multicast (PGM). All Microsoft security patches for both Windows and Office software are available via Microsoft Update or via the individual bulletins detailed below.

MS08-032: Moderate
Titled "Cumulative Security Update of ActiveX Kill Bits (950760)", this bulletin affects users of Microsoft Windows 2000 Service Pack 4; all supported editions of Windows XP; and all editions of Windows Vista including Windows Vista Service Pack 1. The update addresses the issues in CVE-2007-0675. It fixes a publicly reported vulnerability for the Microsoft Speech API that could allow remote code execution if a user viewed a specially crafted Web page using Internet Explorer and has the speech recognition feature in Windows enabled.

MS08-034: Important
Titled "Vulnerability in WINS Could Allow Elevation of Privilege (948745)", this bulletin affects all supported editions of Microsoft Windows 2000 Server and Windows Server 2003. This update addresses the vulnerability detailed in CVE-2008-1451. Microsoft says an attacker could use an elevation of privilege to take complete control of an affected system, and then install programs; view, change, or delete data; or create new accounts.

MS08-035: Important
Titled "Vulnerability in Active Directory Could Allow Denial of Service (953235)", this bulletin is rated Important for all supported editions of Microsoft Windows 2000 Server, and rated Moderate for select editions of Windows XP Professional, Windows Server 2003, and Windows Server 2008. This update addresses the vulnerability detailed in CVE-2008-1445. Microsoft says the vulnerability could be exploited to allow an attacker to cause a denial-of-service condition.

MS08-036: Important
Titled "Vulnerabilities in Pragmatic General Multicast (PGM) Could Allow Denial of Service (950762)", this bulletin is rated Important for all supported editions of Windows XP and Windows Server 2003 and rated Moderate for all supported editions of Windows Vista and Windows Server 2008. This update addresses the vulnerability detailed in CVE-2008-1440 and CVE-2008-1441. Microsoft says "an attacker who successfully exploited this vulnerability could cause a user's system to become non-responsive and to require a restart to restore functionality. Note that the denial-of-service vulnerability would not allow an attacker to execute code or to elevate their user rights, but it could cause the affected system to stop accepting requests."

CNET News.com' Robert Vamosi contributed to this story.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

ZDNet Australia Live

A user from Melbourne measured 12794kbps @ Broadband Speedtest.

4 minutes ago, Click here to find out how fast your internet speed is.

And I though the NBN was all fibre and therefore better than coalition plan! “@zdnetaustralia: now we hear bout NBN Co's wireless component

HulloMail 1.2 for BlackBerry, ZDNet latest review http://bit.ly/d8jeMZ

RT @zdnetaustralia: Telstra completes the majority of a $280m fibre-optic broadband roll-out for NSW DET http://bit.ly/aBmMVm

Let My Smartphone Go! http://bit.ly/9gADuO

RT @zdnetaustralia: With regional Aus getting NBN priority, the cost will not increase http://bit.ly/aAiLXD

Google Instant: search as you type http://dlvr.it/4xtrs (ZDNet)

RT @agusnadhi: Quo Computers' liquid-cooled Core i7 maxQ2 runs OS X, Linux, Windows 7 ...: Still, Quo will tell you the biggest s... http://bit.ly/bdJXfw

RT @phonedevs: Qualcomm looking to Android for initial future developments - ZDNet UK (blog) http://bit.ly/ceYFYk

T-Mobile reveals more details of the upcoming G2 Android device: By Matthew Miller | September 8, 2010, 9:54pm PDT... http://bit.ly/dz8n5g

Back to school with Adobe's Education Exchange http://bit.ly/c4hiVq

NBN roll-out ramps up post election and rejig adds no cost: Conroy http://bit.ly/cnNdET

Freedom of expression online: How far should it go?: By Zack Whittaker | September 8, 2010, 8:26pm PDT Freedom of ... http://bit.ly/9m5ETk

Well id rather see the 40 billion put into making my trip to work 20 minutes faster and reducing the price of houses so that i can actual...

23 minutes ago by rbosward on NBN roll-out rejig adds no cost: Conroy

Oh you're back again old faithful, LOL! So you're no longer claiming "binding agreement" and now asking about a "for...

33 minutes ago by RS on Telstra walks while telco D-team squawks

Even all the spectrum in the world added together is hundreds of times slower than a single hairline strand of Fiber. 100,000,000,000Mbp...

43 minutes ago by Duideka on Much cheaper NBN wins it by a whisker

The nature of wireless is that any frequency band is inherently "capped" - there is a maximum ability to carry data regardless of...

52 minutes ago by Marshall2 on Much cheaper NBN wins it by a whisker

I too am a Telstra customer. I even bought a few TLS shares when they went ex-div a few weeks back (after doing likewise previously and s...

1 hour ago by RS on Telstra 'price squeeze' claims go to ACCC

NBN roll-out rejig adds no cost: Conroy http://bit.ly/d4LIDI via @zdnetaustralia #NBN #openinternet

brando1... If WiMAX2 does actually do as they claim in 2012, great. I'm sure all the NBN supporters (like me) who welcome technology ...

1 hour ago by RS on Exetel chief: 'God help us all' on NBN

Australia has the strictest laws in the world on Telstra controlling it. If you want to see what happens without control go to America. O...

1 hour ago by Brumby on Telstra 'price squeeze' claims go to ACCC

There is some evidence the US Tea Party are bankrolled by The Koch Brothers, as reported in the New Yorker http://www.newyorker.com/repor...

1 hour ago by Blackbobs on Govt, use tech or have tech use you

It's easy to throw comments like that out there. It seems sort of reasonable on the face of it doesn't it? Things are always impr...

1 hour ago by neil_mc on Much cheaper NBN wins it by a whisker

Speaking of political leanings... It was said to be $26B!

1 hour ago by RS on Much cheaper NBN wins it by a whisker

Oh look, I've gained a new troll, LOL... I have NBN leanings big difference what yourr excuse? Don't see you bagging Scott, hmmm...

1 hour ago by RS on Abbott pledges vigilance on NBN stuff-ups

And am I wrong? Is Australia listed on the ASX? Well... Anyway... it has been projected by McKinsey/KPMG that the NBN will be $26B... A...

1 hour ago by RS on Abbott pledges vigilance on NBN stuff-ups

Thanks TimC3, broken promises aside it seems that you either agree or re-iterate everything I have said in this article and previous arti...

1 hour ago by Peter Carr on Open letter against taking Gershon funds

Does that mean that Telstra have been denied access to exchanges by, ah Telstra and Telstra were part of the case against Telstra, where ...

1 hour ago by RS on Telstra 'price squeeze' claims go to ACCC

And you hang other people for their obvious political leanings :)

1 hour ago by mwil19 on Abbott pledges vigilance on NBN stuff-ups

photos of the NBN rollout - http://bit.ly/dy7vrC

Telecoms giant BT is hiring 300 staff across the Asia Pacific region http://bit.ly/bKRHRD http://fb.me/GHfzPjUU

Check out Google Instant search. They say it's going to make searching easier, but is it distracting? Let us know... http://fb.me/DIPEBhCz

RT @fugazied: Fibre in Tasmania #NBN http://www.zdnet.com.au/houses-linked-up-in-tassie-nbn-photos-339304569.htm?omnRef=NULL

This story has been liked 5 times in the last 24 hours!

TechLines 6: email is a jack of all trades http://zdnet.com.au/339305877/ - so I have too much email because I have no process???

RT @zdnetaustralia: Telstra completes the majority of a $280m fibre-optic broadband roll-out for NSW DET http://bit.ly/aBmMVm

Realestate.com.au adopts cloud email http://zdnet.com.au/339305876/

Internode: leave us, but it's not our fault http://zdnet.com.au/339305865/

Internode: leave us, but it's not our fault http://zdnet.com.au/339305865/

really? i'll believe it when i see it ... "ACTA warms to ISPs?" http://j.mp/bcu7uh

Information security systems failed to prevent a Police analyst from leaking information on raids to bikie gang? http://ow.ly/2AYYA

Qld Uni start-up scores MRI grant: Magnetic resonance imaging (MRI) research is about to get another boost in Quee... http://bit.ly/bFw6fk

ISP: TPG announce unlimited Internet plans: http://bit.ly/damLGa

ACCC takes Optus to court (again) for misleading promos http://bit.ly/awhbMJ

Online hospitality tool nets venture capital: One of Australia's most prominent Web 2.0 investment groups, Future ... http://bit.ly/dt1hm0

Aussie software scores at Soccer World Cup: While Australia may not have finished well at the 2010 FIFA World Cup,... http://bit.ly/ctlKeu

@BigPondTeam - ok it's on http://bit.ly/b6Sl8G - they always tell employees last!

Looks like Windsor & Co will be keeping an eye on the roll out of the NBN http://bit.ly/c2kjKU

1) Telstra BigPond47 plans 5%
2) Optus85 plans 1%
3) 39 plans 3%
4) Virgin Mobile7 plans 5%
5) iiNet31 plans 2%

Mobile Phones | Broadband

CBS - ZDNET Australia Partner Services