Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity
    • Development
    • IT Management

    Microsoft to Patch Critical .Net Flaw

    Written by

    Lisa Vaas
    Published July 9, 2007
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Microsoft is issuing six patches on Patch Tuesday on July 10, one of which addresses a critical .Net Framework vulnerability that has the potential to affect a wide array of applications on all of Microsofts actively supported platforms.

      Microsofts .Net Framework, a component thats included with the companys operating systems or which can be added to them, contains chunks of code for common program requirements. Its a core piece of Microsofts product offerings, particularly since its intended to be used by new applications created for Windows. As such, its code library covers many important moving parts in applications, including user interface, data access, database connectivity, cryptography, Web application development, algorithms and network communications—all of which are crucial security points.

      The .Net Framework actually has its own security mechanism that covers CAS (Code Access Security)—a check of permissions granted to code—as well as validation and verification requirements.

      Users wont know until the morning of July 10 when Microsoft delivers its July set of patches exactly what particular chunk or chunks of code the .Net patch covers, but Microsoft has said that the vulnerability could lead to remote code execution, which is considered to be the worst vulnerability, given that it leaves systems vulnerable to hijacking.

      “If you … analyze [the details Microsoft has given in its Security Bulletin Advance Notification, the software affected runs] across all platforms that .Net can be installed in,” said Don Leatham, director of solutions and strategy for PatchLink. “[The affected versions include] the latest .Net technology. Thats why we feel the effects are going to be widespread. On our side, were prepping customers to make sure they get this out as quickly as possible.”

      /zimages/1/28571.gifClick here to read more about Microsoft touting Vistas security.

      Because .Net is so widespread and many programs and internal development efforts are built on the framework, the potential for the patch to break something is substantial. PatchLink is recommending that customers take a phased approach to deploying the patch, by first deploying to a test network upon which organizations should test critical applications and then moving deployment up to increasingly critical business groups or phases.

      Seven .Net versions are affected by the critical vulnerability, which, Microsoft says, can lead to remote code execution. Because of the widespread importance of .Net and the applications that are built using its code components, analysts are advising that organizations update ASAP to patch this vulnerability.

      For details on the affected versions, check Microsofts Security Bulletin Advance Notification page.

      Microsoft is patching two other critical vulnerabilities, both of which can lead to system hijacking, the same as with the .Net vulnerability. One of the patches will address a vulnerability that affects Office and Excel, while the other affects Windows.

      The Excel vulnerability is one to watch out for, given that the application is implicitly trusted by Internet Explorer. Users who visit maliciously crafted sites can click on links that bring up infected .xls files. Because such an embedded Excel file is within an IE Windows frame, brought down through the browser and then through HTTP protocols, IE allows users to navigate through and manipulate such files. This presents a thornier scenario than in the past, when infected files have been sent through e-mail, given that e-mail filters generally can catch and quarantine infected files.

      “If theres something that can be exploited as an embedded document within IE, you cant always catch that,” Leatham said.

      One way to protect against infection via infected embedded Excel files is through IE security settings, enforced through group policy object, that warn against opening embedded files.

      As for what Microsofts leaving unpatched, eEyes Zero-Day Tracker site lists a PowerPoint vulnerability of medium severity thats been out there for 270 days and counting.

      Two other patches, deemed important, are for vulnerabilities that could also lead to remote code execution. One is for Office Publisher, and the other is for Windows XP Professional.

      Vista will be up for patching as well. Leatham noted that the latest operating system could be affected by the critical .Net vulnerability, on top of a moderately important patch—for a vulnerability that could lead to information disclosure—that Microsoft is putting out for Vista.

      Microsoft is also updating its Malicious Software Removal Tool—an update that wont be distributed by SUS (Software Update Services). SUS is, in fact, up for a high-priority, non-security-related upgrade itself. The update for the Microsoft Windows Malicious Software Removal Tool will come out on Windows Update, Microsoft Update, Windows Server Update Services and the Download Center.

      Microsoft is also planning to release four non-security, high-priority updates on MU (Microsoft Update) and WSUS (Windows Server Update Services).

      Check out eWEEK.coms Security Center for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEKs Security Watch blog.

      Lisa Vaas
      Lisa Vaas
      Lisa Vaas is News Editor/Operations for eWEEK.com and also serves as editor of the Database topic center. She has focused on customer relationship management technology, IT salaries and careers, effects of the H1-B visa on the technology workforce, wireless technology, security, and, most recently, databases and the technologies that touch upon them. Her articles have appeared in eWEEK's print edition, on eWEEK.com, and in the startup IT magazine PC Connection.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×