BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

August 2012 Patch Tuesday – Oracle PWNS Microsoft, story at 11!

Posted August 14, 2012    Marc Maiffret

Oracle can be the butt of a lot of jokes when it comes to software security researchers. This Patch Tuesday, however, Oracle has taken things to the next level by not just having poorly secured products of their own but also providing the world with a remote vulnerability within Microsoft Exchange.

Microsoft security bulletin MS12-058 details a vulnerability within Microsoft Exchange that essentially allows for remote system compromise if you send a specifically crafted email to an Exchange server where the email is then read by someone using Outlook Web Access. This is possible because of Microsoft’s usage of Oracle’s Outside In document parsing technology. Oracle’s Outside In technology has multiple vulnerabilities that result in code execution. This bulletin is not only particularly critical because of its ability to compromise Exchange, but also because of the track record that Oracle’s Outside In technology has from a security perspective. Outside In has had multiple vulnerabilities in the past and by judging the types of vulnerabilities being found, we believe there will be more found in the future and that means potentially more Microsoft Exchange compromise vulnerabilities to come. This is a critical flaw to get patched as soon as possible if you are using Microsoft Exchange and OWA.

In another case of a shared component (although this time a Microsoft based one) lending itself to getting peopled owned, we have MS12-060. MS12-060 covers a vulnerability within Microsoft Windows Common Controls and allows for code execution attacks against Microsoft SQL, Office, Commerce Server, Host Integration Server, Visual FoxPro and generally the Visual Basic 6.0 Runtime. It is interesting to note that in the case of Microsoft Office only the 32-bit version is affected while the 64-bit version is not. This is another of the more critical patches to roll out this month.

Internet Explorer of course will never let itself miss out on some Patch Tuesday love and this Patch Tuesday is no exception with bulletin MS12-052. Internet Explorer specifically has vulnerabilities that affect all versions of IE from 6.0 to 9.0 with critical remote code execution across all versions. These vulnerabilities will help to continue fueling the various exploit toolkits used for mass scale hacking attacks and most likely some targeted attacks given the lag time in a typical organization’s time to patch.

On top of more client-side vulnerabilities within Internet Explorer, we also have a nice vulnerability (MS12-057) with Microsoft Office that affects both Office 2007 and 2010 for both 32-bit and 64-bit versions. Rounding out the client-side vulnerabilities for the month we also have MS12-059,a vulnerability within Microsoft Visio affecting only the latest 2010 version, and MS12-056, Jscript and VBScript engine vulnerabilities that only affect 64-bit and Itanium. And don’t worry if you need to elevate code to Kernel from any of these client-side vulnerabilities you have MS12-055 to help you do just that. MS12-055 is a bulletin for a kernel privilege elevation vulnerability that affects all versions of Windows: 32-bit, 64-bit, and Itanium.

Lastly, we have a couple good remote server compromise vulnerabilities with MS12-053 and MS12-054. MS12-053 is yet another Remote Desktop vulnerability, but this time only affecting XP SP3 32-bit versions, while MS12-054 allows for remote code execution on Windows XP and 2003.

In the end, we believe that MS12-058 and MS12-060 are the two most critical vulnerabilities this month and they should be patched as soon as possible.

Leave a Reply

One Response to “August 2012 Patch Tuesday – Oracle PWNS Microsoft, story at 11!”

  1. February 2013 Patch Tuesday: Hide Your Servers, Hide Your Clients | BeyondTrust

    [...] Server 2010 for SharePoint had its own collection of CVEs addressed in MS12-067. As we predicted in August 2012, more Outside In vulnerabilities have been found that affect Microsoft Exchange. We believe this [...]

    February 12, 2013 10:25:01, Reply

Additional articles

gartner market guide image - aug 2014

Introducing the Gartner Market Guide for Privileged Account Management

Posted July 29, 2014    Chris Burd

Gartner recently released a new Market Guide for Privileged Account Management (PAM), and we’d like to share a complimentary copy with you. The report includes PAM market analysis and direction, vendor overviews, and recommendations for selecting PAM solutions for your environment. BeyondTrust is one of two representative vendors (out of 20) to address all solution…

Tags:
, , , , , , , ,
Integrating Least Privilege and Password Management to Solve Account Security Challenges

Integrating Least Privilege and Password Management to Solve Account Security Challenges

Posted July 24, 2014    Morey Haber

There is a reason all BeyondTrust Privileged Account Management (PAM) solutions share the PowerBroker name: They all inherently enable you to reduce user-based risk and can be integrated under a centralized IT risk management platform. Here’s one common use case that demonstrates how this integration changes the playing field. Consider the challenge of privileged access:…

Tags:
, , , , ,
PowerBroker Password Safe Password Age Report

Reshaping Privileged Password Management with Password Safe 5.2

Posted July 21, 2014    Martin Cannard

Today, we’re pleased to unveil the latest edition of our privileged password management solution, PowerBroker Password Safe. I’ll start with a brief intro of what’s new and then tell you a little about the driving factors behind Password Safe development. New features for mitigating password risk and ensuring accountability enterprise-wide Here’s the 10,000-foot overview of…

Tags:
, , ,