Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

February 11, 2004 12:00 AM

Controversial Microsoft Security Fixes Have Company on Security Defensive

Windows IT Pro
InstantDoc ID #41744
Rating: (0)

   Late yesterday, Microsoft issued its planned monthly set of security updates, but this month the updates are more serious and controversial than usual. One of the fixes, rated as critical, applies to "an extremely deep and pervasive technology in Windows" that attackers can compromise to take over PCs, but the flaw was discovered 7 months ago and fixed only this week. Security experts describe the flaw as one of the most devastating ever, and Microsoft recommends that all users download and install the patch for this problem as soon as possible. The timing couldn't be worse for the company: Microsoft Chairman and Chief Software Architect Bill Gates recently alleged that Windows is more secure than any OS alternatives because the system has been so thoroughly tested in the real world through constant attacks; Gates will also keynote an upcoming industry security event in San Francisco. So why did Microsoft take so long to fix the flaw, leaving Windows users open to potentially devastating electronic attacks?
   "This is one of the most serious Microsoft vulnerabilities ever released," Marc Maiffret, chief hacking officer and cofounder of eEye Digital Security, the company that discovered two of the Windows flaws Microsoft revealed this week, said. "The breadth of systems affected is probably the largest ever. This is something that will let you get into Internet servers, internal networks--pretty much any system." Alarmingly, eEye discovered the flaws last July and agreed to keep quiet until Microsoft could fix them. But Maiffret described the lag time between eEye's discoveries and Microsoft's fixes as "totally unacceptable." Microsoft defends the whopping 7 months it took to fix the flaws as necessary because the company needed to ensure that a patch to such central Windows components didn't break software or cause other problems. "We really took the steps to make sure our investigation was as broad and deep as possible," Microsoft Security Program Manager Stephen Toulouse said.
   The critical security flaw exists in a Windows component called the ASN.1 library, which interacts with multiple Windows features, including file sharing and digital certificates. The flaw affects every Windows version from Windows NT 4.0 to Windows Server 2003, and includes all desktop and server variants of these systems. Interestingly, attackers can compromise the flaw with a simple buffer-overrun attack, a common type of attack that Microsoft has wrestled with since its Trustworthy Computing code review 2 years ago. Both XP Service Pack 2 (SP2), due midyear, and Windows 2003 SP1, due in late 2004, will include new memory-protection features designed to thwart most buffer-overrun attacks. You can learn more about the patch on the Microsoft Web site, but Windows users should use Automatic Updates or Windows Update to download and install each of the security patches Microsoft issued this month.

Related Content:

ARTICLE TOOLS

Comments
  • Toby Ovod-Everett
    8 years ago
    Feb 18, 2004

    If you go to http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/Bulletin/MS04-007.asp and expand "Security Update Information", and then expand the areas underneath that, you'll find dates on the dlls for different platforms.

    Windows 2003 - Oct 23
    Windows 2003 64 - Oct 23
    Windows XP - Sep 19
    Windows XP 64 - Oct 23
    Windows 2000 - Sep 19
    Windows NT - Sep 21

    It looks to me like Microsoft had the patches written in short order, but then wanted to do extensive regression testing against everything that uses msasn1.dll.

  • David
    8 years ago
    Feb 15, 2004

    "Microsoft Chairman and Chief Software Architect Bill Gates recently alleged that Windows is more secure than any OS alternatives because the system has been so thoroughly tested in the real world through constant attacks;"

    Nice one Bill! I assume the testing is still ongoing then?

    "So why did Microsoft take so long to fix the flaw, leaving Windows users open to potentially devastating electronic attacks?"

    Perhaps because the flaw touched very large portions of Windows, and perhaps other Microsoft apps. It would take some time to figure out what needed to be changed, and then to test it and make sure nothing bad happened. Windows is so modular you know?

    "The breadth of systems affected is probably the largest ever. This is something that will let you get into Internet servers, internal networks--pretty much any system."

    Nice one. So all of that security in Windows can be bypassed completely? Nice to know. This seems to go right to the heart of Windows here as well.

    "Microsoft defends the whopping 7 months it took to fix the flaws as necessary because the company needed to ensure that a patch to such central Windows components didn't break software or cause other problems."

    I believe them here. This seemed to affect a lot of things.

    "Interestingly, attackers can compromise the flaw with a simple buffer-overrun attack, a common type of attack that Microsoft has wrestled with since its Trustworthy Computing code review 2 years ago."

    Nothing is immune to buffer-overuns, but it seems that someone can always get to the vital parts of the Windows system with these attacks.

    "Both XP Service Pack 2 (SP2), due midyear, and Windows 2003 SP1, due in late 2004, will include new memory-protection features designed to thwart most buffer-overrun attacks."

    Sounds rather like chroot. Nice one.

  • Wayne
    8 years ago
    Feb 12, 2004

    Actually the worst thing you can do is use Microsoft's "Automatic Update Service."

    1) Some of the patchs contain changes to the Windows EULA which take away some of the original rights you were given, and increase Microsoft's rights.

    2) Microsoft has had many problems with patches, i.e. systems stop working, software is now broken, etc.

    I run 3 Win98, 1 Win95, and one WinXP computer at home. None are patched, all are extremly secure. There are five simple steps to secure a Windows computer.

    1) Install another browser such as Mozilla. Never use IE. If you can uninstall IE (Win98 and later will not allow this thought there are third party tools which will help you do it)

    2) Install another email client (and uninstall Outlook Express). Mozilla has a decent email client.

    3) Install a hardware firewall - Linksys makes excellant units.

    4) Install Zonealarm (Especially on WinXP computers). When you set it up if any program trys to access the net AND YOU DIDN"T START IT tell Zonealarm to block it. Zonealarm is free for personal use.

    5) Install OpenOffice, StarOffice, or Easy Office instead of Microsoft Office. All are more secure than the Microsoft Product, and far cheaper. You can pay for the router and extra network cabling from the savings.

    Wayne

  • Bruce
    8 years ago
    Feb 12, 2004

    If you go to Cert, you will find that ASN.1 vulnerabilities hit every OS possible, including Apple OS X, via OpenSSL which ships on most OS's these days, including Cisco routers.

    http://www.securityfocus.com/bid/8732/info/

  • Sam Jones
    8 years ago
    Feb 12, 2004

    This article sounds like an article written by someone who don't have anything to write about. They fixed the damn thing so get over it. Move on

You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.