Review: HP UMPC 2133
If you're prepared to put up with the misses HP's new UMPC still delivers some real hits. »more
Add your event to ENN
Take a few moment to add your upcoming event to ENN's tech calendar. It's free. »more
Web Pick: ReQall
If you are great at forgetting your best ideas before you captured them for posterity this will help. »more
IN ASSOCIATION WITH
Entropy & Nokia - making security matter
 
Home -   Events -   Training 

Light month for Microsoft security
12-09-2007
by Ciara O'Brien

It was a light 'Patch Tuesday' for Microsoft this month, with only one critical flaw identified in the tech firm's regular security update.

In fact, the monthly update -- issued on 11 September -- included patches for only four flaws, a record for 2007. The fixes were for vulnerabilities discovered in Windows, Visual Studio and the MSN and Windows Live Messenger software.

The most serious flaw was discovered in Microsoft Agent, which could allow a malicious user to attack a machine using remotely executed code.

Although rated only as "important", the flaw found in the Messenger software has already been the subject of exploit code published on the internet. Users who are fooled into accepting a webcam or video chat from a malicious user can find their systems hijacked by rogue code.

Another flaw, affecting Visual Studio, required users to open an RPT file to trigger the remote code execution, while Windows Services for UNIX 3.0, Windows Services for UNIX 3.5, and Subsystem for UNIX-based Applications were hit by the fourth vulnerability. A fifth patch had been expected, but was unexpectedly left out of the bundle.

The light patch bundle makes a change from recent months, when Microsoft hit record highs for 2007. The biggest batch of patches this year was released in February, when 20 vulnerabilities were fixed in a security bulletin that consisted of 12 patches. A significant security update was also released in August, when 14 flaws were fixed in nine security updates. Eight of these security holes were rated as "critical".

Meanwhile, voice over IP firm Skype is experiencing some problems of its own, with an infected JPEG image spreading a worm via its instant messaging system. The worm, which is known as W32.Pykspa.D or W32/Skipi.A, is spreading to users' machines through a link to a JPEG file. If users click on the link, they view a bitmap of bubbles -- a Windows default bitmap graphic -- and are more than likely infected by the worm.

Once compromised, infected machines begin to send the worm to other Skype users. The worm also tries to close down security software and block updates to antivirus programs.

Create eAlertPrinter-friendly versionemail a friendRSS feed
ENN Blog
Going Dutch
If you've come to rely on the web to secure business in Europe you may be interested to note that Blacknight is claiming to be the first Irish company accredited » Read more
spacer

 Get RSS Feed
Choose one or all of our RSS Newsfeed Channels
» Find out more
Top News
Google is planning to help advertisers find the ideal audience for their ads with the release of a new tool that measures internet use. » Read more

Who's who in pr
Full listing of Irish PR firms, including high-tech specialists. » Click here
subscribe
Not a member yet?
Sign up free, click here
To change your ENN Newsletter and alerts preferences here
spacer
opinion
Bringing science back to life
Science courses continue to prove unpopular with students, but some new initiatives are trying to change that trend.
» Read more
Hosted by Telecity
enn corporate
Complete copywriting services
ENN CorporateDo you need skilled writers to put together compelling prose for your company? Why not check out the new-look corporate services site from ENN and see how we can put our skills to your use.»more
events
8 July
International Trade Skillnet Online Market Course
9am, Europa Academy, Swords
» View more events
» Post your event on ENN
reader survey
Let us know how to make ENN better! Take our reader's survey.