BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Microsoft Patch Tuesday – July 2011

Posted July 12, 2011    Chris Silva

I’m really starting to enjoy the “odd” months, Microsoft kept to their pattern and released only four security bulletins today. A welcome reprieve from last month’s sixteen bulletins.

The only “Critical” rated vulnerability released today affects the Windows Bluetooth 2.1 stack. This particular vulnerability is somewhat interesting due to the attack vector. As you know, Bluetooth is mostly used to connect peripherals over a short range, creating a “Personal Area Network”. As such, an attacker would need to be in relatively close proximity to the victim, even if using a Bluetooth sniffing antenna.

The good news is that by default Windows doesn’t broadcast your 48-bit Bluetooth address, so your computer is not normally “discoverable”. This address is required to connect to your computer and exploit the vulnerability. While there are ways of obtaining this address from communication intercepted between two devices, they are both expensive and time consuming. As such, the chances of a “walk-by” attack while you are drinking your Frappuccino at Starbucks is relatively low.

Even so, it is recommend that you disable Bluetooth (Uncheck “Allow Bluetooth devices to connect to this computer”) if you do not have any essential devices that require it. At a minimum, make sure that “Allow Bluetooth devices to find this computer” is unchecked in your Bluetooth Settings dialog.

For more details, remember to sign up for tomorrow’s Vulnerability Expert Forum (VEF). As there are only a handful of Microsoft bulletins to cover, there should be ample time to touch on other topics and answer your questions.

As for the security updates, here are our recommendations. Retina Network Security Scanner customers can view the list of audits associated with these bulletins.

Deploy As Soon As Possible

MS11-053 – Vulnerability in Bluetooth Stack Could Allow Remote Code Execution (2566220)
Recommendation: Deploy patches as soon as possible. Until the patch can be applied, open the Bluetooth Settings dialog box. Uncheck the box next to the “Allow Bluetooth devices to connect to this computer” setting. Note: this will prevent all Bluetooth devices from connecting to affected systems, which will mean Bluetooth mice and keyboards will be affected, as well.

MS11-054 – Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2555917)
Recommendation: Deploy patches as soon as possible as no mitigation is currently available.

MS11-055 – Vulnerability in Microsoft Visio Could Allow Remote Code Execution (2560847)
Recommendation: Deploy patches as soon as possible. Until the patch can be applied, block ports 139 and 445 using a firewall, prevent the WebClient service from running, and prevent DLLs from being loaded from WebDAV and remote shares.

MS11-056 – Vulnerabilities in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2507938)
Recommendation: Deploy patches as soon as possible as no mitigation is currently available.

Leave a Reply

Additional articles

How To Implement The Australian Signals Directorate’s Top 4 Strategies

Posted October 20, 2014    Morey Haber

The Australian Signals Directorate (ASD), also known as the Defence Signals Directorate, has developed a list of strategies to mitigate targeted cyber intrusions. The recommended strategies were developed through ASD’s extensive experience in operational cyber security, including responding to serious security intrusions and performing vulnerability assessments and penetration testing for Australian government agencies. These recommendations…

Tags:
, , , ,
asp-mvc

Exploiting MS14-059 because sometimes XSS is fun, sometimes…

Posted October 17, 2014    BeyondTrust Research Team

This October, Microsoft has provided a security update for System.Web.Mvc.dll which addresses a ‘Security Feature Bypass’. The vulnerability itself is in ASP.NET MVC technology and given its wide adoption we thought we would take a closer look. Referring to the bulletin we can glean a few useful pieces of information: “A cross-site scripting (XSS) vulnerability exists…

Tags:
4bestpracticesaudits-blog

Four Best Practices for Passing Privileged Account Audits

Posted October 16, 2014    Chris Burd

Like most IT organizations, your team may periodically face the “dreaded” task of being audited. Your process for delegating privileged access to desktops, servers, and infrastructure devices is a massive target for the auditor’s microscope. An audit’s findings can have significant implications on technology and business strategy, so it’s critical to make sure you’re prepared…

Tags:
, , , ,