Patch Tuesday Monthly Security Briefing may 2011

In this issue:

April Showers Bring May Flowers, and Patch Tuesday is No Exception

1 Critical, 1 Important

Patch Tuesday Security Briefing

Last month it poured when Microsoft released 17 security bulletins that addressed a total of 64 vulnerabilities. For today's Patch Tuesday, we have a light load; however, both patches address remote code execution and one is critical. So both require immediate attention. The critical patch MS11-035 Vulnerability in WINS addresses an issue with all supported versions of Windows server - 2003, 2008 and 2008 R2 and exposes the server to a remote code execution attack and should be a high priority if you're running any of the Windows server platforms. The second issue MS11-036 Vulnerability in PowerPoint addresses an issue in Microsoft PowerPoint for Microsoft Office for the Windows environment XP, 2003 and 2007 however Office 2010 is not impacted. Important to note that also impacted is Microsoft Office for the Mac.

Of further note are the recent changes to the Exploitability Index, which now reflects the likelihood of a vulnerability becoming the subject of an attack in the next 30 days. In addition, there is a new component called the "Denial of Service Risk Score" that can be used to determine the risk of a vulnerability becoming the subject of a Denial of Service attack. More details on the changes ...Read More »

Get Started Today »


FREE Trial Offers

Try our award-winning products and solutions NOW »

Endpoint Management and Security Suite Trial »

Intelligent Whitelisting Trial »

AntiVirus Trial »

Application Control Trial »

Device Control Trial »

Patch and Remediation Trial »

Risk Manager Trial »

Discontinued July 7, 2011:

Lumension®Patch and Remediation v 6.4 SP2 and Lower

If you are on Lumension® Patch and Remediation v.6.4 SP2 (and lower) it is critically important you immediately start planning for the migration of your systems to Lumension® Patch and Remediation v.7.1 on the Lumension® Endpoint Management and Security Suite (L.E.M.S.S.) platform to ensure uninterrupted patch content support starting July 8, 2011.

Visit the Upgrade Center Today »


FREE Security Tools


Application Scanner 2.0

Discover all applications running on your network



Get it Now »


Device Scanner

Discover every removable device ever connected to your endpoints



Get it Now »


Vulnerability Scanner

Discover all OS and application vulnerabilities on your network



Get it Now »

Bulletins

» Highest Priority

MS11-035   Vulnerability in WINS Could Allow Remote Code Execution (2524426)

» Important

MS11-036   Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution (2545814)

Updates Outside of Microsoft

While it is Microsoft Patch Tuesday, as usual, Microsoft products are not the only ones that require patches. Other issues include a new Day Zero vulnerability discovered by VUPNEN for Google Chrome that bypasses the Sandboxing as well as ASLR/DEP protections without executing a kernel vulnerability. The exploit has been described as "very sophisticated" and works on all Windows systems 32/64 bit.

  • A YouTube video of the exploit can be found here

Also, yesterday we learned that Skype issued a patch for a security hole in its Skype 5 client for Mac. The discovered vulnerability would have allowed potential hackers to build a self-replicating worm targeting Mac OS X. With today’s acquisition news, it seems we’ll be hearing about patches from Skype on the second Tuesday of the month from now on…

Apple Security Content

Adobe Security Content

Mozilla Security Content

Security Forum
High Level Decision Making

Reputation services allow you to apply social networking logic to protect the business without creating gaping holes in your defense posture. Find out how Reputation can help you make informed whitelist decisions.

Webcast
Using Intelligent Whitelisting to Effectively and Efficiently Combat Today's Malware
May 12, 2011 3 pm ET

Join us on Thursday, May 12 at 3pm EST as Randy Franklin Smith from UltimateWindowsSecurity explains how you must implement a defense-in-depth approach that goes beyond standalone anti-virus to effectively prevent malware.

Whitepaper
Endpoint Management and Security Buyers Guide

Read this guide as we examine the five factors to look for in endpoint management and security solutions that will help reduce endpoint cost, simplify management and improve overall performance.

Visit the Security Forum »

Register for the Webcast »

Download the Whitepaper »