Original URL: http://www.channelregister.co.uk/2007/12/12/dec_black_tuesday_update/
Three of the seven patches Microsoft released on Tuesday earn the dread rating of critical.
Updates involving flaws in handling streaming media by Microsoft DirectX, bugs in Windows Media Format Runtime, and multiple vulnerabilities in IE all pose a severe risk.
In all three cases the vulnerabilities addressed by the update create a possible means for miscreants to smuggle malware onto, or otherwise attack, vulnerable Windows boxes. But the IE update deserves special attention since hackers are actively exploiting the bug to attack vulnerable machines, the SANS Institute's Internet Storm Centre warns (http://isc.sans.org/diary.html?storyid=3735).
The remaining four "important" updates address bugs including a brace of bugs in Windows Vista and a security bug in DRM software from Macrovision that comes bundled with Windows. Macrovision issued a patch to address flaws in its SafeDisk utility in November, which is just as well because the bug has become the target of various attacks by crackers.
Microsoft's December patch summary can be found here (https://www.microsoft.com/technet/security/bulletin/ms07-dec.mspx). A rather more colourful (graphical) overview from SANS can be found here (http://isc.sans.org/diary.html?storyid=3735). ®
Attackers hose down Microsoft's Jet DB Engine (26 March 2008)
http://www.channelregister.co.uk/2008/03/26/jet_database_engine_security_flaws/
Critical Outlook and Excel bugs star in March Patch Tuesday (12 March 2008)
http://www.channelregister.co.uk/2008/03/12/march_patch_tuesday/
Microsoft dishes out six critical updates (13 February 2008)
http://www.channelregister.co.uk/2008/02/13/patch_tuesday_february/
Microsoft plugs 'critical' hole in Vista (8 January 2008)
http://www.theregister.co.uk/2008/01/08/microsoft_january_patch_release/
MS preps critical Vista patch for Tuesday (4 January 2008)
http://www.channelregister.co.uk/2008/01/04/ms_patch_tuesday_pre_alert/
Microsoft readies seven patches for Tuesday (6 December 2007)
http://www.channelregister.co.uk/2007/12/06/microsoft_announces_7_patches_for_december/
Windows update offers defence against shell bug (14 November 2007)
http://www.channelregister.co.uk/2007/11/14/windows_novemeber_patch_update/
Macrovision update plugs zero-day DRM exploit (6 November 2007)
http://www.channelregister.co.uk/2007/11/06/macrovision_drm_update/
Fight malware by upgrading to Vista, urges MS (23 October 2007)
http://www.channelregister.co.uk/2007/10/23/rsa_vista_security_pitch/
Oracle readies mega-update patching 51 security holes (13 October 2007)
http://www.channelregister.co.uk/2007/10/13/oracle_readies_security_updates/
Exploit Wednesday follows Patch Tuesday Word update (11 October 2007)
http://www.channelregister.co.uk/2007/10/11/exploit_wednesday/
© Copyright 2008