CIO Today

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
Daily Briefing for Technology's Top Decision-Makers
Tuesday, February 9th 
Home
Enterprise Software
Enterprise Hardware
Network Security
Compliance
CRM Systems
Data Storage
Chips & Processors
Operating Systems
Communications
World Wide Web
Wireless Tech
Small Business
CIO Issues
Business Briefing
After Hours
Press Releases
 

Advertisement
Computing

Patch Tuesday: Microsoft Fixes 20 Security Bugs

Patch Tuesday: Microsoft Fixes 20 Security Bugs
February 14, 2007 9:32AM

Bookmark and Share
Microsoft's Patch Tuesday this month brought 20 new fixes, covering a broad set of bugs in Windows and Office applications. Eleven of the patches were labeled "critical," the highest ranking in Microsoft's scoring system. Windows users with Microsoft's Automatic Updates feature enabled do not have to do anything to get these patches. They will be rolled out automatically.


Microsoft Relevant Products/Services has released its February round of security updates, complete with some long-awaited patches for its Office productivity suite of applications. This month's Patch Tuesday addresses multiple critical fixes for vulnerabilities in both Office and Microsoft's line of security products. Altogether, Microsoft patched 20 flaws with its current release.

Eleven of the patches were labeled "critical," the highest ranking in Microsoft's scoring system Relevant Products/Services. Eight of the patches fix Office flaws, including six vulnerabilities in Word and one each for Excel and PowerPoint. While all of these patches are significant from a security standpoint, the patch called MS07-010 seems to be stealing the spotlight.

MS07-010 fixes a critical bug in the malware-scanning engine used by Windows Relevant Products/Services OneCare, Windows Defender, and Forefront Security and Antigen products. Hackers could exploit the flaw to take complete control of a victim's PC by feeding malformed PDFs to the computer through e-mail. The flaw is of particular concern to analysts.

"This continues the trend of malware authors targeting widely deployed Microsoft business applications and services," said Dave Marcus, security research and communications Relevant Products/Services manager at McAfee's Avert Labs. "Malware authors continue to find unknown or unpatched vulnerabilities in popular applications and services which are then used in zero-day attacks, putting both business and consumer data Relevant Products/Services at risk."

Security Focus

The MS07-010 patch, which comes on the heels of last week's RSA conference at which Microsoft Chairman Bill Gates delivered a keynote emphasizing the company's focus on security, came as a surprise to some.

"While this release does not contain any vulnerabilities that directly exploit the Vista core operating system, programs like Windows Defender, Antigen, and Windows Live OneCare are applications that can be installed on Windows operating systems including Vista," said Amol Sarwate, manager of the vulnerability research lab at Qualys.

According to Minoo Hamilton, senior vulnerability researcher for nCircle, Microsoft's continuing investment in security is starting to pay off, with many products becoming more secure Relevant Products/Services in more recent versions. However, Hamilton said, MS07-010 is a critical vulnerability that demonstrates there is more work to be done.

"This vulnerability shows that many Microsoft products are still vulnerable to some of the same type of attack techniques that have been in play for the last couple of years," he noted. "Consumers and enterprises using the latest versions of Windows need to be aware that any and all of these products are still vulnerable." (continued...)

1  |  2  |  Next Page >

Advertisement



 Computing
1. MS: Windows 7 Doesn't Hurt Battery
2. Tips for More Windows 7 Productivity
3. The Pros and Cons of Apple's iPad
4. IBM Power7 Server Takes on Big Load
5. China Cyberattacks: Pervasive Threat


advertisement

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  Macworld Focuses on Mobile Apps
  MS: Windows 7 Doesn't Hurt Battery
  Nexus One 'Support' Passes the Buck
  MS: Russian Pirates Scamming Us
  Google May Make Gmail More Social

 Technology Marketplace
Compliance
Stand out from other IS Professionals and increase your earning potential.®).
 
Enterprise Hardware
Now is the best time to buy a new APC Smart-UPS!
HP ProLiant G6 Servers: Perform like a superstar, Save like an accountant www.hp.com
 
Enterprise I.T.
Learn how Microsoft server upgrades can create efficiencies
Stand out from other IS Professionals and increase your earning potential.®).
 
Hardware
Find out why now is the best time to buy a new APC Smart-UPS!
 
Microsoft/Windows
Read about how to add efficiencies with Microsoft Virtualization.
 
Network Security
AT&T Synaptic Compute as a Service. Boost your power on demand.
 
Mobile Enterprise Spotlight

To Love or Not To Love: Apple iPad Pros and Cons
Now that the iPad has officially been announced, opinions are rolling in on this device that combines the features of an iPod, e-reader, and tablet PC. Will the iPad turn fewer heads than the iPhone?

Analysts See iPad Price Drop, with Some Cannibalization
Just weeks before Apple officially rolls out the iPad, financial analysts are making pricing predictions. But could the analysis itself hinder the initial demand for the pricey tablet computer?

Bar Codes Go Mobile, Get Hip Again
For decades, retailers have used patterns of black dots and lines to encode data onto products. Now, bar codes are gaining favor as an easy way for cell-phone users to view ads and other data instantly.

Advertisement
Enterprise Software Spotlight

Macworld Focuses on Mobile Apps as Apple Stays Away
Macworld 2010 kicked off in San Francisco showcasing hundreds of Mac products and services, expert advice, and demonstrations -- but this year mobile apps may steal the show.

Google May Add Facebook, Twitter Links to Gmail
Google will reportedly roll more social-networking features into Gmail, the fastest-growing e-mail service. The new features could save users the trouble of switching to Facebook or Twitter.

SAP CEO Abruptly Resigns; Co-CEOs Will Take Over
Business-software maker SAP announced an abrupt strategic shift in the corporate suite with CEO Léo Apotheker resigning, to be replaced by co-CEOs Bill McDermott (left) and Jim Hagemann Snabe (right).

Advertisement
Enterprise Hardware Spotlight

Microsoft Says Battery Woes Not Caused By Windows 7
Battery problems on Windows 7 machines are not caused by the operating system. That's the position of Stephen Sinofsky, head of the Windows division, in a long posting on the Windows engineering blog.

IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."

'Dead Simple, Dirt Cheap' JooJoo Tablet Shipping Soon
The JooJoo, a web-browsing tablet device that is the subject of a high-profile legal dispute, appears on track to reach buyers at the end of February, but the tablet scene has dramatically changed.

Advertisement
Enterprise Security Spotlight

Chinese Cyberattacks Seen as a Pervasive Threat
Google's accusation that e-mail accounts were hacked from China landed like a bombshell because it cast light on a problem few firms will discuss: the pervasive threat from China-based cyberattacks.

Patch Tuesday Release Will Tie Microsoft's Record
After a light start to the year, Microsoft is getting ready to dump a heavy load on the shoulders of IT administrators. On Patch Tuesday next week, Microsoft will release 13 patches.

Cybersecurity Vendors Look Hot in 2010
Tech-security companies are poised to become Wall Street darlings this year, thanks in part to Google's tiff with China, which reinforced an already positive outlook for major security vendors.

Advertisement
Navigation
CIO Today
Home/Top News | Enterprise Software | Enterprise Hardware | Network Security | Compliance | CRM Systems | Data Storage
Chips & Processors | Operating Systems | Communications | World Wide Web | Wireless Tech | Small Business | CIO Issues
Business Briefing | After Hours | Press Releases
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 CIO Today. All rights reserved. Article rating technology by Blogowogo.