<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Praetorian Prefect &#187; patch</title>
	<atom:link href="http://praetorianprefect.com/archives/tag/patch/feed/" rel="self" type="application/rss+xml" />
	<link>http://praetorianprefect.com</link>
	<description>Information security, a little slower...a little deeper</description>
	<lastBuildDate>Thu, 29 Jul 2010 16:38:31 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>March&#8217;s Patch Tuesday</title>
		<link>http://praetorianprefect.com/archives/2010/03/3473/</link>
		<comments>http://praetorianprefect.com/archives/2010/03/3473/#comments</comments>
		<pubDate>Tue, 09 Mar 2010 20:38:40 +0000</pubDate>
		<dc:creator>Simon Price</dc:creator>
				<category><![CDATA[Administration]]></category>
		<category><![CDATA[Patch Management]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[excel]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[office]]></category>
		<category><![CDATA[office for mac]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[patch tuesday]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=3473</guid>
		<description><![CDATA[<a href="http://praetorianprefect.com/wp-content/uploads/2010/03/msft_logo.jpg"><img src="http://praetorianprefect.com/wp-content/uploads/2010/03/msft_logo.jpg" alt="msft_logo" title="msft_logo" width="150" height="150" class="alignleft size-full wp-image-3484" /></a>

Today is patch Tuesday for March 2010, and Microsoft has released two security bulletins for this round of updates, neither of which are deemed critical. The second bulletin addresses seven different vulnerabilities across various versions of Microsoft Office Excel.]]></description>
			<content:encoded><![CDATA[<p><a href="http://praetorianprefect.com/wp-content/uploads/2010/03/msft_logo.jpg"><img src="http://praetorianprefect.com/wp-content/uploads/2010/03/msft_logo.jpg" alt="msft_logo" title="msft_logo" width="150" height="150" class="alignleft size-full wp-image-3484" /></a></p>

<p>Today is patch Tuesday for March 2010, and Microsoft has released two security bulletins for this round of updates, neither of which are deemed critical. The second bulletin addresses seven different vulnerabilities across various versions of Microsoft Office Excel.</p>

<hr />

<p><strong>ID:</strong> <a href="http://www.microsoft.com/technet/security/bulletin/ms10-016.mspx">MS10-016</a><br />
<strong>Title:</strong> Vulnerabilities in in Windows Movie Maker Could Allow Remote Code Execution<br />
<strong>Microsoft Severity:</strong> Important<br /></p>

<p><strong>Summary:</strong> There is a buffer overflow in the Windows Movie Maker and MS Producer 2003 which can lead to code execution. Movie Maker 2.1 is included with Windows XP SP2 and SP3, and Movie Maker 6.0 is included with Vista. Movie Maker 2.6 is an optional download for Vista and Windows 7.<br /></p>

<p><strong>Praetorian&#8217;s Recommendation:</strong> This is deemed important instead of critical due to the user having to run content which exploits the vulnerability. A user would have to be tricked into opening a Movie Maker project file (mswmm) to be exploited. This can be updated in your next patch cycle, and is not considered urgent. <br /></p>

<hr />

<p><strong>ID:</strong> <a href="http://www.microsoft.com/technet/security/Bulletin/MS10-017.mspx">MS10-017</a><br />
<strong>Title:</strong> Vulnerability in Microsoft Office Excel Could Allow Remote Code Execution<br />
<strong>Microsoft Severity:</strong> Important<br /></p>

<p><strong>Summary:</strong> This update addresses seven different vulnerabilities related to Microsoft Office Excel. Each vulnerability may affect one or more of the following versions: Office Excel 2003 SP3, Office Excel 2003 SP3, Office Excel 2007 SP1 and SP2, Office 2004 for Mac, Office 2008 for Mac, Open XML File Format Converter for Mac, Office Excel Viewer SP1 and SP2, Office Compatibility Pack for Word, Excel, and Powerpoint 2007 File Formats SP1 and SP2, and Office SharePoint Server 2007 SP1 and SP2.<br /></p>

<p><strong>Praetorian&#8217;s Recommendation:</strong> Although the same requirement exists as MS10-016 for users to open malicious files, Excel formats are more recognizable and phishing and social engineering techniques can be more successful with a known or common file format. This can be updated in your next patch cycle, but should warrant more attention than MS10-017.<br /></p>

<hr />

<p><strong>Related Posts:</strong></p>
<ul>
<li><a href="http://praetorianprefect.com/archives/2010/06/iphone-4-ordering-and-session-switching/">iPhone 4 Ordering and Session Switching</a></li>
<li><a href="http://praetorianprefect.com/archives/2010/05/mays-patch-tuesday/">May&#8217;s Patch Tuesday</a></li>
<li><a href="http://praetorianprefect.com/archives/2010/03/press-f1-for-help-pwned/">Press F1 for Help, pwned.</a></li>
<li><a href="http://praetorianprefect.com/archives/2010/02/februarys-patch-tuesday/">February&#8217;s Patch Tuesday</a></li>
<li><a href="http://praetorianprefect.com/archives/2010/01/disable-acrobat-reader-pdf-in-the-enterprise/">Using Group Policy to Disable JavaScript in Adobe PDF Files</a></li>
</ul><br />
]]></content:encoded>
			<wfw:commentRss>http://praetorianprefect.com/archives/2010/03/3473/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Six Bulletins in Last Patch Tuesday of 2009</title>
		<link>http://praetorianprefect.com/archives/2009/12/six-bulletins-in-last-patch-tuesday-of-2009/</link>
		<comments>http://praetorianprefect.com/archives/2009/12/six-bulletins-in-last-patch-tuesday-of-2009/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 19:39:55 +0000</pubDate>
		<dc:creator>Simon Price</dc:creator>
				<category><![CDATA[Administration]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[flash]]></category>
		<category><![CDATA[ie]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[patch tuesday]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=2088</guid>
		<description><![CDATA[Today marks the last Microsoft patch Tuesday of 2009, and Microsoft has released patches to six bulletins:




MS09-071 &#8211; Vulnerabilities in Internet Authentication Service Could Allow Remote Code Execution (974318)
MS09-074 &#8211; Vulnerability in Microsoft Office Project Could Allow Remote Code Execution (967183) 
MS09-072 &#8211; Cumulative Security Update for Internet Explorer (976325) 
MS09-069 &#8211; Vulnerability in Local [...]]]></description>
			<content:encoded><![CDATA[<p>Today marks the last Microsoft patch Tuesday of 2009, and Microsoft has released patches to six bulletins:</p>

<p><a href="http://praetorianprefect.com/wp-content/uploads/2009/12/image_31_3.png"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image_3[1]_3" border="0" alt="image_3[1]_3" src="http://praetorianprefect.com/wp-content/uploads/2009/12/image_31_3.png" width="69" height="81" /></a></p>

<ul>
<li><strong>MS09-071</strong> &#8211; Vulnerabilities in Internet Authentication Service Could Allow Remote Code Execution (974318)</li>
<li><strong>MS09-074</strong> &#8211; Vulnerability in Microsoft Office Project Could Allow Remote Code Execution (967183) </li>
<li><strong>MS09-072</strong> &#8211; Cumulative Security Update for Internet Explorer (976325) </li>
<li><strong>MS09-069</strong> &#8211; Vulnerability in Local Security Authority Subsystem Service Could Allow Denial of Service (974392) </li>
<li><strong>MS09-070</strong> &#8211; Vulnerabilities in Active Directory Federation Services Could Allow Remote Code Execution (971726) </li>
<li><strong>MS09-073</strong> &#8211; Vulnerability in WordPad and Office Text Converters Could Allow Remote Code Execution (975539) </li>
</ul>

<h3>Severity Levels</h3>

<p>Microsoft has a <a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx" target="_blank">rating system</a> for bulletins which includes: Critical, Important, Moderate, and Low. The severity levels I provide below are not directly from Microsoft. For example, MS will give an important rating when exploitation could result in compromise of availability, as in a denial of service. MS09-069 can result in a denial of service, however, the attacker must already be authenticated. For this reason I drop the severity to Low.</p>

<h3>Bulletin Summaries</h3>

<hr />

<p><strong>Bulletin:</strong> MS09-071<br/>
<strong>Recommended Action:</strong> Update Windows 2008 Server (32-bit and 64-bit) which have IAS configured to use PEAP with MS-CHAP v2 authentication.<br/>
<strong>My Severity Rating:</strong> Moderate, should patch the above mentioned software.</p>

<p>This update addresses two vulnerabilities in the Internet Authentication Service (IAS). One is an IAS memory corruption vulnerability and the second is an authentication bypass vulnerability in MS-CHAP authentication. Client operating systems contain the vulnerable code but the components are not used in a way to make them vulnerable.</p>

<hr />

<p><strong>Bulletin:</strong> MS09-074<br/>
<strong>Recommended Action:</strong> Update MS Project 2000 SR-1.<br/>
<strong>My Severity Rating:</strong> Important for Project Software</p>

<p>This update addresses a vulnerability in Microsoft Project which can cause remote code execution when a specially crafted Project file is opened.&#160; Microsoft Project 2000 SR-1, Project 2002 SP1 and Project 2003 SP3 are affected.</p>

<hr />

<p><strong>Bulletin:</strong> MS09-074<br/>
<strong>Recommended Action:</strong> Update Internet Explorer<br/>
<strong>My Severity Rating</strong> Critical</p>

<p>This update addresses five difference vulnerabilities with at least one or more affected every version of Internet Explorer. Attackers can host malicious code which can lead remote code execution on vulnerable systems. Any issues that lead to remote execution in IE should be addressed immediately; even if you are confident about not browsing malicious sites, a known site, <a href="http://praetorianprefect.com/archives/2009/12/pentagon-web-pwned/">such as the Pentagon web site</a>, could be used to automatically execute or redirect you to malicious code using cross-site scripting.</p>

<hr />

<p><strong>Bulletin:</strong> MS09-069<br/>
<strong>Recommended Action:</strong> Update Windows 2000, Windows XP and Windows 2003<br/>
<strong>My Severity Rating:</strong> Low</p>

<p>A vulnerability in LSASS can cause a denial of service. The attacker must be authenticated and communicating through IPSEC.</p>

<hr />

<p><strong>Bulletin:</strong> MS09-070<br/>
<strong>Recommended Action:</strong> Update Windows 2003 and Windows 2008 Servers<br/>
<strong>My Severity Rating:</strong> Low</p>

<p>This update addresses two vulnerabilities in Active Directory Federation Services, one which can be used to spoof an authenticated user and the second which can cause remote code execution. The spoofing requires access to a workstation and browser recently used by a targeted user and the remote code execution requires the attacker to have valid logon credentials to the vulnerable server.</p>

<hr />

<p><strong>Bulletin:</strong> MS09-069     <br/>
<strong>Recommended Action:</strong> Update Windows XP SP3 and/or Office 2003 SP3<br/>
<strong>My Severity Rating:</strong> Moderate</p>

<p>A vulnerability in text converters in WordPad and Office can cause remote code execution. Malicious code can be hosted on a website to trigger an exploit, however, an attempt would cause a dialog box to appear prompting the user to open the file (unless the option to “Always ask before opening this type of file” has been unchecked).</p>

<hr />

<h3>Adobe</h3>

<p><a href="http://praetorianprefect.com/wp-content/uploads/2009/12/adobelq.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="adobe-lq" border="0" alt="adobe-lq" src="http://praetorianprefect.com/wp-content/uploads/2009/12/adobelq_thumb.png" width="47" height="76" /></a></p>

<p>Adobe has mirrored the patch Tuesday schedule of releasing patches on the first Tuesday of the month. The severity ratings also follow the same definitions a s Microsoft’s.</p>

<p>Adobe has two advisories for this month:</p>

<hr />

<p><strong>Bulletin:</strong> APSA09-06     <br />
<strong>Recommended Action:</strong> Update Adobe Illustrator CS4 and earlier. (Avail Jan 8)     <br />
<strong>My Severity Rating:</strong> Low</p>

<p>A vulnerability in Illustrator CS4 and earlier could lead to remote code execution. The target is required to open a malicious eps file.</p>

<hr />

<p><strong>Bulletin:</strong> APSA09-17     <br />
<strong>Recommended Action:</strong> Update Adobe Flash Player and Adobe AIR<br/>
<strong>My Severity Rating:</strong> Low</p>

<p>Adobe states this is a critical update and it is scheduled for release today, but does not provide details of the update.</p>

<h3>Updates</h3>

<p>Adobe has released details on the Flash Player update. The update addresses six vulnerabilities, five which can lead to remote execution and one to information disclosure. The vulnerabilities were identified in Flash Player version 10.0.32.18 and earlier.</p>

<h3>References</h3>

<ul>
<li><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-dec.mspx">Microsoft&#8217;s December Bulletins</a></li>
<li><a href="http://www.adobe.com/support/security/">Adobe&#8217;s Security Advisories</a></li>
</ul>

<p><strong>Related Posts:</strong></p>
<ul>
<li><a href="http://praetorianprefect.com/archives/2010/07/turning-an-atm-into-a-slot-machine/">Turning an ATM into a Slot Machine</a></li>
<li><a href="http://praetorianprefect.com/archives/2010/06/iphone-4-ordering-and-session-switching/">iPhone 4 Ordering and Session Switching</a></li>
<li><a href="http://praetorianprefect.com/archives/2010/05/mays-patch-tuesday/">May&#8217;s Patch Tuesday</a></li>
<li><a href="http://praetorianprefect.com/archives/2010/03/3473/">March&#8217;s Patch Tuesday</a></li>
<li><a href="http://praetorianprefect.com/archives/2010/03/press-f1-for-help-pwned/">Press F1 for Help, pwned.</a></li>
</ul><br />
]]></content:encoded>
			<wfw:commentRss>http://praetorianprefect.com/archives/2009/12/six-bulletins-in-last-patch-tuesday-of-2009/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Adobe to release critical update on patch Tuesday</title>
		<link>http://praetorianprefect.com/archives/2009/10/adobe-to-release-critical-update-on-patch-tuesday/</link>
		<comments>http://praetorianprefect.com/archives/2009/10/adobe-to-release-critical-update-on-patch-tuesday/#comments</comments>
		<pubDate>Fri, 09 Oct 2009 15:03:50 +0000</pubDate>
		<dc:creator>Simon Price</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[patch tuesday]]></category>
		<category><![CDATA[reader]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[zero-day]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=882</guid>
		<description><![CDATA[A new zero-day vulnerability in Adobe Reader and Acrobat 9.1.3 has been identified by Chia-Ching Fang and the Taiwanese Information and Communication Security Technology Service Center that allows an attacker to remotely execute arbitrary code. The attack is seeded by providing via e-mail or download a specially crafted PDF file which in current examples will then drop a malware executable as well as an unaffected pdf file.]]></description>
			<content:encoded><![CDATA[<p><a href="http://praetorianprefect.com/wp-content/uploads/2009/10/adobelq1.png"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="adobe-lq" border="0" alt="adobe-lq" src="http://praetorianprefect.com/wp-content/uploads/2009/10/adobelq_thumb1.png" width="47" height="76" /></a></p>

<p>A new zero-day vulnerability in Adobe Reader and Acrobat 9.1.3 has been identified by Chia-Ching Fang and the Taiwanese Information and Communication Security Technology Service Center that allows an attacker to remotely execute arbitrary code. The attack is seeded by providing via e-mail or download a specially crafted PDF file which in current examples will then drop a malware executable as well as an unaffected pdf file. McAfee is identifying this under Exploit-PDF.m, and has a signature for a specific Trojan already identified. This is the fourth PDF related zero-day attack of 2009, and a further incentive for enterprises to bring patching of applications in line with processes for operating system patching.</p>

<p>The crafted PDF file contains a Javascript which is used to execute arbitrary code via a technique known as heap spraying. The initial shell code jumps program execution to a second shell code, which in turn executes a malicious file that creates a backdoor (remote access to the infected computer). <a href="http://blog.trendmicro.com/new-adobe-zero-day-exploit/">Trend Micro</a> is identifying this malware as a Protux variant. Protux backdoors provide user level access to the machine and have been associated as the payloads of Microsoft Office (Word, PowerPoint, Excel, Access) as well as previous Adobe Reader exploits. The Protux family of Trojans has been around since at least 2007.</p>

<p>The identification of this exploit has prompted Adobe to announce release of a critical patch for release on Tuesday, October 13th. The company posted a <a href="http://www.adobe.com/support/security/bulletins/apsb09-15.html">security advisory</a> yesterday, announcing plans to release the update to “resolve critical security issues&#8221;. The vulnerability is being exploited, although it is unclear how widespread the attacks are. Adobe asserts that the vulnerability is being exploited in “limited, targeted attacks” limited to Windows operating systems although the vulnerability itself also exists for other operating systems.</p>

<blockquote>
  <p>“There are reports that this issue is being exploited in the wild in limited targeted attacks”     <br /> – David Lenoe of Adobe</p>
</blockquote>

<p>Vupen Security posted an <a href="http://www.vupen.com/english/advisories/2009/2851&quot;">advisory</a> on the vulnerability (CVE-2009-3459) which states that the issue is an unspecified memory corruption error, which could be exploited allowing attackers to comprise a system remotely.</p>

<h3>Workarounds</h3>

<h4>Disabling Javascript on Adobe Acrobat</h4>

<p>Adobe notes that disabling Javascript mitigates against the specific exploit identified, although it would be possible to create a variant that does not rely on Javascript.  To disable Javascript in Adobe Reader or Acrobat, select Edit > Preferences, select the JavaScript option on the left, and uncheck the <i>Enable Acrobat JavaScript</i> option as shown.</p>

<p><div id="attachment_916" class="wp-caption alignnone" style="width: 650px"><a href="http://praetorianprefect.com/wp-content/uploads/2009/10/AcrobatPreferences.png"><img src="http://praetorianprefect.com/wp-content/uploads/2009/10/AcrobatPreferences.png" alt="Uncheck to disable Acrobat JavaScript" title="AcrobatPreferences" width="640" height="424" class="size-full wp-image-916" /></a><p class="wp-caption-text">Uncheck to disable Acrobat JavaScript</p></div>
<br /></p>

<h4>Data Execution Prevention</h4>

<p>Also, users with DEP enabled on Windows Vista or Windows 7 are protected from this exploit. Data Execution Prevention (DEP) performs additional checks on memory to help prevent malicious code from running, designed to prevent buffer overflow attacks. To enable DEP on Windows for all or individual programs, proceed to Control Panel -> System and Maintenance -> System, click on Advanced System Settings, under Performance click Settings, and finally under the Data Execution Prevention tab click <i>Turn on DEP for all programs and services except those I select</i>. If you can not find Acrobat in the list of programs, click Add and browse to the Acrobat executable (.exe) file and click Open.  For more information on DEP settings, visit the <a href="http://windows.microsoft.com/en-us/windows-vista/Change-Data-Execution-Prevention-settings">Microsoft help page</a>.</p>

<h3>In Conclusion</h3>

<p>In June Adobe moved to the same Tuesday patch management schedule that Microsoft and Oracle previously adopted. This latest zero-day exploit represents another opportunity to address an ongoing issue for organizations: that patch management must extend beyond just the operating system level. While enterprises focus on ensuring the latest Microsoft updates to the desktop and server environment, applications, such as Adobe Reader, fail to be a part of the the same rigorous patch management exercise.</p>

<p>Qualys demonstrated this problem when the first Adobe exploit was released this year in February, APSA09-01.  While a fix was released on March 10th (demonstrated by the red line in their graph), by April 27th there was still no clear reduction in the number of vulnerable machines. A 30 day patch management cycle, including testing of the patch before full enterprise release, would have shown a steep drop off on or about April 10th:</p>

<p><div id="attachment_914" class="wp-caption alignnone" style="width: 609px"><a href="http://praetorianprefect.com/wp-content/uploads/2009/10/adobe_april_09.png"><img src="http://praetorianprefect.com/wp-content/uploads/2009/10/adobe_april_09.png" alt="Source: http://laws.qualys.com/lawsblog/2009/04/new-adobe-0-day-vulnerability.html" title="adobe_april_09" width="599" height="341" class="size-full wp-image-914" /></a><p class="wp-caption-text">Source: http://laws.qualys.com/lawsblog/2009/04/new-adobe-0-day-vulnerability.html</p></div>
<br />
In March Adobe patched a two month old zero day exploit, followed by another patch in May to block a second zero day attack. In July a fix was released for a Flash PDF related flaw.  As evidenced by the four exploits thus far this year, Adobe applications are becoming an increasingly attractive target for bad actors.
<br /><br /></p>

<p><strong>Related Posts:</strong></p>
<ul>
<li><a href="http://praetorianprefect.com/archives/2010/06/iphone-4-ordering-and-session-switching/">iPhone 4 Ordering and Session Switching</a></li>
<li><a href="http://praetorianprefect.com/archives/2010/05/mays-patch-tuesday/">May&#8217;s Patch Tuesday</a></li>
<li><a href="http://praetorianprefect.com/archives/2010/03/3473/">March&#8217;s Patch Tuesday</a></li>
<li><a href="http://praetorianprefect.com/archives/2010/03/press-f1-for-help-pwned/">Press F1 for Help, pwned.</a></li>
<li><a href="http://praetorianprefect.com/archives/2010/01/the-aurora-ie-exploit-in-action/">The &#8220;Aurora&#8221; IE Exploit Used Against Google in Action</a></li>
</ul><br />
]]></content:encoded>
			<wfw:commentRss>http://praetorianprefect.com/archives/2009/10/adobe-to-release-critical-update-on-patch-tuesday/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
