Patch Tuesday Monthly Security Briefing march 2011

In this issue:

Light Patch Load From Microsoft This Month - But More Than Enough Work to Go Around

1 Critical, 2 Important

Patch Tuesday Security Briefing - March 2011

This Patch Tuesday wasn't very large, but it was serious. Two of the patches we saw were in Windows, and the third in Office. All patches addressed issues providing for remote code execution, which is top of mind for IT flaw remediation specialists.

If you're using the Remote Desktop Client, MS11-017 should be your top priority followed by MS11-015 and finally MS11-016. Those not using Remote Desktop Client but regularly sending / receiving large media files should focus on MS11-015 first.

Microsoft may have cleaned up a lot of loose ends with the release of Windows 7 and Windows Server 2008 R2 Service Pack 1 last month, leaving little to address this Patch Tuesday. That being said, the patches released today did not address the recently disclosed MHTML issues and we expect a resolution in April's patch release.

Other notable activity this Patch Tuesday period was the Google Android Kill-Switch patch that remotely removed 58 malicious applications from 260,000 Android Phones.

Since the release of the iPhone, Apple has taken a lot of heat from the user community over their decision to effectively whitelist and explicitly control which applications are permitted to run on their iPhone product. Many ran to the Android as an alternative because of its more open stance on applications where anyone can write an Android application and place it the Android Market.

The wake-up call came for Android owners a little more than a week ago when over 50 malicious applications were found uploaded and distributed in the Google Android Market. Google removed them a few days later but not before an estimated 260,000 people downloaded the affected applications. This event effectively illustrates the differences in the whitelist approach employed by Apple and the inherently reactive blacklist model Google uses.

This is a classic case of the blacklist model in contrast to the whitelist model. Apple chose to deploy their product having explicit control of the applications and Google chose to blacklist.

It will be interesting to see how this increasingly mobile landscape continues to evolve and how the bad guys evolve in their ability to exploit it.

Get Started Today »


FREE Trial Offers

Try our award-winning products and solutions NOW »

AntiVirus Trial »

Application Control Trial »

Device Control Trial »

Patch and Remediation Trial »

Risk Manager Trial »

Have You Migrated Yet?

Gain complete control of your endpoints!

Begin taking advantage of all the latest Lumension technology and product innovations that the Lumension® Endpoint Management and Security Suite has to offer. This solution is designed to reduce your endpoint complexity and TCO, while improving your overall endpoint security and compliance posture.

Visit the Upgrade Center Today »

FREE Security Tools


Application Scanner 2.0 Beta

Discover all applications running on your network



Get it Now »


Device Scanner

Discover every removable device ever connected to your endpoints



Get it Now »


Vulnerability Scanner

Discover all OS and application vulnerabilities on your network



Get it Now »

Bulletins

» Highest Priority

MS11-015   Vulnerabilities in Windows Media Could Allow Remote Code Execution (2510030)

» Important

MS11-017   Vulnerability in Remote Desktop Client Could Allow Remote Code Execution (2508062)
MS11-016

 

  Vulnerability in Microsoft Groove Could Allow Remote Code Execution (2494047)

Updates Outside of Microsoft

March is a light release for Microsoft with only 3 bulletins however the big news from Microsoft was the release of Service Pack 1 for Windows 7 and Windows Server 2008 R2 on February 22. This release contains many security and stability updates and should be on your roll-out plan.

Other notable security releases since the last Patch Tuesday include:

 

All include fixes for critical security vulnerabilities.

Webcast
Lumension® Intelligent Whitelisting:
Sneak Peek Webcast
March 16, 2011

Lumension customers are invited to a sneak peek of Lumension® Intelligent Whitelisting™, the industry's first integrated application whitelisting solution that combines patch management, application control, antivirus, and trust-based change management into a single, unified workflow.

Threat Level
Lumension® Endpoint Intelligence Center

To identify and validate known applications, L.E.I.C. consolidates malware, vulnerability, patch, and application information with relational cloud based intelligence. Quickly query any unknown hash files found on your network and see context as to the type of application, software category and whether it is from a known or unknown source.

Webcast
The New Role of Application Control in a Zero-Day Reality
March 23, 2011

Learn how application control, also known as whitelisting, allows organizations to efficiently block unknown and unauthorized applications from executing by default – thereby preventing zero-day attacks automatically.

Register for the Webcast »

Visit the Threat Center »

Register for the Webcast »