Wednesday 11 January 2012

Patch Tuesday - Jan 2012


With this January Microsoft Patch Tuesday update, we see a set of 7 updates; 1 with the rating of Critical and 6 with the rating of Important. This is a moderately sized update from Microsoft and the potential impact for the updates is likely to be low.
As part of the Patch Tuesday Security Update analysis performed by the ChangeBASE team, we have seen a small number of potential compatibility issues, including some which were caused by the fifth update in this release, MS12-005, where vulnerabilities in Microsoft Windows could allow Remote Code Execution.

Given the nature of the changes and updates included in each of these patches, most systems will require a reboot to successfully implement any and all of the patches and updates released in this January Patch Tuesday release cycle.
Here is a sample of the results for two applications tested for compatibility with these updates:
Top: MS12-005: Vulnerabilities in Microsoft Windows Could Allow Remote Code Execution.
Bottom: MS12-006: Vulnerabilities in SSL/TLS Could Allow Information Disclosure.




Testing Summary
  • MS12-001 : Vulnerability in Windows Kernel Could Allow Security Feature Bypass (2644615)
  • MS12-002 : Vulnerability in Windows Object Packager Could Allow Remote Code Execution (2603381)
  • MS12-003 : Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2646524)
  • MS12-004 : Vulnerabilities in Windows Media Could Allow Remote Code Execution (2636391)
  • MS12-005 : Vulnerability in Microsoft Windows Could Allow Remote Code Execution (2584146)
  • MS12-006 : Vulnerability in SSL/TLS Could Allow Information Disclosure (2643584)
  • MS12-007 : Vulnerability in AntiXSS Library Could Allow Information Disclosure (2607664)


Patch NameTotal
Issues
Matches
Affected
RebootRatingRAG
Microsoft Security Bulletin MS12-001<1%<1%YESGreen
Microsoft Security Bulletin MS12-002<1%<1%YESGreen
Microsoft Security Bulletin MS12-003<1%<1%YESGreen
Microsoft Security Bulletin MS12-004<1%<1%YESAmber
Microsoft Security Bulletin MS12-005<1%<1%YESAmber
Microsoft Security Bulletin MS12-006<1%<1%YESAmber
Microsoft Security Bulletin MS12-007<1%<1%YESGreen

Legend:
No IssueNo Issues Detected
Applications flagged as GREEN have no issues identified against them.
FixablePotentially fixable application Impact
An AMBER issue is one that pertains to the installation routine. A packager can change things in the installation routine and so can AOK Workbench. Anywhere an issue is found and a change can be made to the installation routine to get rid of it we will flag it as amber. AOK Workbench fixes almost all of the issues it flags as amber. For the few issues that require a decision to be made, a packager can manually remediate these using the issue data provided by AOK Workbench.
SeriousSerious Compatibility Issue
A RED issue is generally one that pertains to how the code or actual program works. In this case we will flag as Red issues where a package tries to use objects or functions that have been deprecated from the OS or where their use has been restricted. In this case there are no changes that a packager (or AOK Workbench) can make to the install routine to fix the problem. The problem needs to be dealt with at the program code level by the programmer that wrote it or by providing a more up to date driver. However it is reasonably straightforward once a programmer has the information provided by AOK Workbench to make these changes. For vendor MSIs an upgrade may be required.

Security Update Detailed Summary
MS12-001Vulnerability in Windows Kernel Could Allow Security Feature Bypass (2644615)
DescriptionThis security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow an attacker to bypass the SafeSEH security feature in a software application. An attacker could then use other vulnerabilities to leverage the structured exception handler to run arbitrary code. Only software applications that were compiled using Microsoft Visual C++ .NET 2003 can be used to exploit this vulnerability.
PayloadNtdll.dll, Wntdll.dll, Updspapi.dll
ImpactImportant - Security Feature Bypass

MS12-002Vulnerability in Windows Object Packager Could Allow Remote Code Execution (2603381)
DescriptionThis security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a legitimate file with an embedded packaged object that is located in the same network directory as a specially crafted executable file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
PayloadNo specific files affected
ImpactImportant - Remote Code Execution

MS12-003Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2646524)
DescriptionThe vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application. The attacker could then take complete control of the affected system and install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability can only be exploited on systems configured with a Chinese, Japanese, or Korean system locale.
PayloadWinsrv.dll, Updspapi.dll
ImpactImportant - Elevation of Privilege

MS12-004Vulnerabilities in Windows Media Could Allow Remote Code Execution (2636391)
DescriptionThis security update resolves two privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow remote code execution if a user opens a specially crafted media file. An attacker who successfully exploited the vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
PayloadMciseq.dll, Winmm.dll, Updspapi.dll
ImpactCritical - Remote Code Execution

MS12-005Vulnerability in Microsoft Windows Could Allow Remote Code Execution (2584146)
DescriptionThis security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a specially crafted Microsoft Office file containing a malicious embedded ClickOnce application. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
PayloadPackager.exe, Updspapi.dll
ImpactImportant - Remote Code Execution

MS12-006Vulnerability in SSL/TLS Could Allow Information Disclosure (2643584)
DescriptionThis security update resolves a publicly disclosed vulnerability in SSL 3.0 and TLS 1.0. This vulnerability affects the protocol itself and is not specific to the Windows operating system. The vulnerability could allow information disclosure if an attacker intercepts encrypted web traffic served from an affected system. TLS 1.1, TLS 1.2, and all cipher suites that do not use CBC mode are not affected.
PayloadSchannel.dll, Winhttp.dll, Updspapi.dll
ImpactImportant - Information Disclosure

MS12-007Vulnerability in AntiXSS Library Could Allow Information Disclosure (2607664)
DescriptionThis security update resolves one privately reported vulnerability in the Microsoft Anti-Cross Site Scripting (AntiXSS) Library. The vulnerability could allow information disclosure if a an attacker passes a malicious script to a website using the sanitization function of the AntiXSS Library. The consequences of the disclosure of that information depend on the nature of the information itself. Note that this vulnerability would not allow an attacker to execute code or to elevate the attacker's user rights directly, but it could be used to produce information that could be used to try to further compromise the affected system. Only sites that use the sanitization module of the AntiXSS Library are affected by this vulnerability.
PayloadNo specific files affected
ImpactImportant - Information Disclosure


*All results are based on a ChangeBASE Application Compatibility Lab's test portfolio of over 1,000 applications.

No comments: