Menu
Patch Tuesday: Windows 8, Exchange in danger

Patch Tuesday: Windows 8, Exchange in danger

Microsoft is issuing critical patches for flaws found in Windows 7, 8 and RT desktops as well as for the spam and malware filter for Microsoft Exchange server.

The first affects not only the Windows clients but also Windows Server 2008 and 2012, and if unpatched leaves them vulnerable to attacks that could result in interlopers remotely executing code on victim machines.

+ Also on Network World: How Microsoft and Mobilespaces are using the cloud for MDM | Satya Nadella and Bill Gates's apron strings | So you think you know networking? Quiz II +

The second critical bulletin flags a vulnerability in Windows Forefront, which is security for Exchange. It could lead to attackers disabling Forefront, leaving mail recipients open to malware in emails or give attackers entry into the Mail server itself, says Wolfgang Kandek, the CTO of Qualys.

That makes this patch worth paying attention to, says Ross Barrett, a senior manager of security engineering at Rapid7. "Given a remote code execution in a perimeter service like Forefront, I'd have to say that this is the highest priority patching issue this month," he says.

With a total of only five bulletins overall, that makes for the second light patching month in a row, he notes.

"This month's bulletins are unusual in that they don't touch older versions of Windows or Internet Explorer," says Tyler Reguly, manager of security research for Tripwire.

Kandek says usually Microsoft issues Internet Explorer patches every other month, so it's unusual that there were none in January and none again this month. But he expects a thorough patching next month just days before the annual Pwn2own browser-hacking contest. "I think it would make sense to have a fully patched browser at that point," he says. Successful hacks from the competition may prey on flaws that are known now and could be patched by the time exploits against them come out at Pwn2own, he says.

He notes that separately, Adobe has issued an update to its Flash Player because there are live exploits for a vulnerability. Generally the Adobe patches align with Microsoft's Patch Tuesday, but because an exploit has been found in the wild, it issued the fix early. Users should install the update right away, he says.

Tim Greene covers Microsoft and unified communications for Network World and writes the Mostly Microsoft blog. Reach him at tgreene@nww.com and follow him on Twitter@Tim_Greene.

Read more about software in Network World's Software section.

Subscribe here for up-to-date channel news

Follow Us

Join the New Zealand Reseller News newsletter!

Error: Please check your email address.

Tags MicrosoftNetworkingsecurityRapid7infrastructure managementpatch managementsoftwarequalysmanagement

Featured

Slideshows

StorageCraft celebrates high achievers at its inaugural A/NZ Partner Awards

StorageCraft celebrates high achievers at its inaugural A/NZ Partner Awards

Revealed at a glitzy bash in Sydney at the Ivy Penthouse, the first StorageCraft Partner Awards locally saw the vendor honour its top-performing partners with ASI Solutions, SMBiT Pro, Webroot, ACA Pacific and Soft Solutions New Zealand taking home the top awards. Photos by Maria Stefina.

StorageCraft celebrates high achievers at its inaugural A/NZ Partner Awards
Kiwi resellers make a splash on Synnex and Lenovo RotoVegas road trip

Kiwi resellers make a splash on Synnex and Lenovo RotoVegas road trip

​Synnex and Lenovo hosted 18 resellers for an action-packed weekend adventure in RotoVegas, taking in white water rafting on the Kaituna River, as well as quad biking and dinner at Stratosfare​, overlooking Lake Rotorua at the top of Mount Ngongotaha​. Photos by Synnex.

Kiwi resellers make a splash on Synnex and Lenovo RotoVegas road trip
Show Comments