Showing posts with label Tuesday. Show all posts
Showing posts with label Tuesday. Show all posts

Thursday, 11 July 2013

Patch Tuesday: Malicious fonts bedevil Microsoft Windows

Of the six critical security bulletins Microsoft issued in its Patch Tuesday monthly release of software updates, three address a vulnerability in how Microsoft software renders fonts.

"Fonts have become really complicated," said Wolfgang Kandek, chief technology officer for compliance and security software company Qualys. "There is real processing going on when you print a character, and that complexity can be attacked."

The number of critical bulletins Microsoft released this month is a bit higher than normal, Kandek said. Typically, Microsoft will issue about two or three critical bulletins on Patch Tuesday, which occurs on the second Tuesday of each month. This month half the bulletins -- MS13-052, MS13-053 and MS13-054 -- address how Microsoft systems handle the rendering of TrueType fonts.

With this vulnerability, an attacker can embed malicious values in a font description that would overrun the memory allocated to the font-drawing routine, and write into sections of memory reserved for other operations. The font instructions could be provided to Windows or Internet Explorer (IE) by way of a Web page or a document.

"Depending on where this happens, this can be quite serious," Kandek said.

Windows, for instance, renders all characters onto the screen as a system user, not as a standard user, which has fewer system privileges. An exploit of a font-rendering vulnerability could "go right into the operating system and take control at that level," Kandek said.

Overall, Microsoft issued six critical bulletins, covering Windows OS, the .NET Framework, Silverlight, Office, Visual Studio, Lync and IE. A seventh bulletin, labeled as important, covers the Windows Defender security software.

All six of the critical bulletins include remote code execution vulnerabilities, which can be used to provide attackers with illicit access to machines.

Seventeen of the 34 vulnerabilities covered in the bulletins address IE. "Researchers continue to find flaws in IE, and the attack surface is pretty big," Kandek said, referring to how Microsoft is now supporting five different versions of the browser. The vulnerabilities affect IE versions six through 10 that run on Windows XP, Windows Vista, Windows 7, Windows 8, Windows Server 2003, Windows Server 2008 and Windows RT.

"The major problem there is that users or companies still maintain old versions of the browser. We would be better off if everyone was on the newer version" of IE, Kandek said.

One Windows vulnerability, which affects memory management, has already been publicly revealed, and has been used for an exploit that can run on the Metasploit penetration testing software. Security researchers are urging administrators to update their own versions of Windows XP, Windows Vista, Windows 7, Windows 8 and Windows 2008, Windows 2012 and Windows RT as soon as possible.

"July is one of the uglier releases we've seen from Microsoft this year. To say that all Microsoft products are affected and everything is affected critically is not an overstatement," wrote Lumension security and forensic analyst Paul Henry in an email statement. "It's difficult to prioritize one or two because all the bulletins likely need your attention this Patch Tuesday."

In addition to Microsoft patches, administrators should also take a look at Adobe's monthly set of patches, also released Tuesday. They cover vulnerabilities in Adobe Flash, Shockwave and ColdFusion, which is server-side software for rendering websites.

Follow me on Twitter @sajilpl

July's Patch Tuesday fixes 6 critical Microsoft flaws

If you use the Windows operating system, or just about any of the core products offered by Microsoft, it's time to install some crucial updates. Today, Microsoft pushed out seven new security bulletins—along with their accompanying patches—as well as a new policy that affects both third-party apps and those developed by Microsoft itself.

Of the seven security bulletins, six of them are rated Critical, while the remaining one is ranked as Important. The Critical security bulletins affect Windows, Internet Explorer, Microsoft Office, Silverlight, and more. The Important security bulletin addresses a privilege elevation flaw in the Windows Defender security software, so that definitely shouldn’t be ignored.
Microsoft squashes a number of bugs
with seven new security bulletins.
Ross Barrett, senior manager of security engineering at Rapid7, stressed this isn't your typical Patch Tuesday announcement. “Basically everything in the core Microsoft world is affected by one or more of these; every supported OS, every version of MS Office, Lync, Silverlight, Visual Studio and .NET. It’s going to be a busy time for security teams everywhere.”

Tyler Reguly, technical manager of security research and development at Tripwire, said it can be difficult to prioritize patch deployment when almost all of them are Critical. “Luckily, there's safety in the known, so customers should patch Internet Explorer first, a common theme for Microsoft patch drops.”

That means start with MS13-055—the ever-popular cumulative patch update for the Internet Explorer web browser. Reguly feels that MS13-053 should be next in line for attention after MS13-055 because it fixes a vulnerability that is already being exploited in the wild.

Qualys CTO Wolfgang Kandek agrees that MS13-053 and MS13-055 are the top priorities, but in his mind the urgency is flip-flopped. In a blog post, Kandek believes that MS13-053 is the most crucial because it affects all versions of the Windows OS, and addresses vulnerabilities that are being actively exploited. Kandek warns, “The most likely attack vector is through end users browsing a malicious web page or opening an infected document, which results in Remote Code Execution that gives control of the affected machine to the attacker.”
Developers--including Microsoft--will have only 180 days to address critical vulnerabilities.
The other big news from Microsoft is the unveiling of a new policy that places a countdown clock on dealing with vulnerabilities. Craig Young, Tripwire security researcher, explained, “Under the new policy, any app in any of the four [Microsoft] app stores will be given 180 days to resolve reported code execution bugs. This policy applies to 3rd-party developers as well as Microsoft’s own applications and is a great addition to Microsoft’s existing policy of scanning and reviewing app submissions.”

This new policy from Microsoft is significant for businesses that rely on Microsoft platforms and devices. Six months is still a long time for a vulnerability to be in place—especially Critical or Important vulnerabilities that can potentially be exploited to execute malicious code remotely—but the policy shows Microsoft's continued commitment to security. The policy applies to all apps available through the Windows Store, Windows Phone Store, Office Store, or Azure Marketplace."

The policy does not, however, apply to vulnerabilities that are being actively exploited in the wild. Flaws that pose an imminent or ongoing threat are handled with greater urgency. According to a blog post from Microsoft, "In those cases, we’ll work with the developer to have an update available as soon as possible and may remove the app from the store earlier."

If you have Automatic Updates enabled, sit back and relax, but plan on your system rebooting at some point to finish applying all of the necessary patches. If you don’t use Automatic Updates, get cracking! You’ve got a lot of Critical patches to install.

Follow me on Twitter @sajilpl

Thursday, 27 June 2013

Box Office Report: 'This Is the End' Opens to Impressive $2.2 Million Tuesday Night

This Is The End Guys Around Coffee Table - H 2013

Seth Rogen and Evan Goldeberg's This Is the End earned a strong $2.2 million as it rolled out in select theaters Tuesday night at 7 p.m.

The R-rated end-of-the-world comedy -- marking the directorial debut of Goldberg and Rogen, who also stars -- is hoping for a pleasing five-day debut in the low $30 million range, which would recoup the film's $32 million budget. It opens everywhere in North America on Wednesday.

PHOTOS: 'This is The End' Premiere: The Apocalypse Gets Funny

In terms of comps, Summit Entertainment's ensemble magician pic Now You See Me grossed $1.5 million in Thursday night shows late last month on its way to a $29.4 million.

Also starring Jonah Hill, James Franco, Jay Baruchel, Danny McBride, Craig Robinson, Michael Cera and Emma Watson, This is the End hopes to serve as counterprogramming to Warner Bros. and Legendary Pictures' Superman entry Man of Steel, which begins rolling out Thursday night in the U.S.

In the comedy, the actors -- all playing fictional versions of themselves -- are attending a star-studded party at Franco's house when the apocalypse begins and they're forced to work together to survive. The feature is based on a short film created by Rogen and Baruchel in 2007 titled Jay and Seth vs. The Apocalypse. Rogen and Goldberg also co-wrote the scripts for Superbad, The Green Hornet and The Watch.

This Is the End, which will play in more than 2,900 theaters, also features several other cameos during the early scenes at Franco's house party, including appearances by Rihanna, Mindy Kaling, Jason Segel, Paul Rudd and Kevin Hart.

In terms of sheer gross, the comedy will be eclipsed once the highly anticipated Man of Steel debuts. Zack Snyder's superhero action film, produced by Christopher Nolan, opens in 24 foreign markets, including in South Korea on Thursday.

Among other major markets, Man of Steel opens in the U.K. and Mexico on Friday. The following weekend, the $225 million tentpole opens in 26 additional markets, including China, France, Germany, Italy, Russia and Spain.

Based on tracking, box-office observers are predicting a North American debut in the $85 million to $100 million range.

VIDEO: 'Man of Steel's' Henry Cavill on Fame: 'Going to Starbucks Is Now a Thing of the Past'

British actor Henry Cavill stars as Clark Kent in the origin tale, which sees his character trying to hide his superpowers and live a normal life on Earth. Amy Adams stars as Lois Lane, and Michael Shannon takes on the role of the menacing General Zod.

With a story by Christopher Nolan and David S. Goyer, and a script by Goyer, Man of Steel will have a special screening at the Los Angeles Film Festival on Wednesday. It opens in limited release in the U.S. Thursday night, with a wide release on Friday in more than 4,200 theaters.

Warners and Legendary turned to Nolan as a producer on the project after he successfully revived the Batman franchise with his Dark Knight trilogy. In the summer of 2005, Nolan's Batman Begins opened to $48.7 million and had incredible staying power.

Twitter: @sajilpl