It's a busy day for IT administrators and information security professionals. Not only is today Microsoft's Patch Tuesday for the month of April, it is also the day of Adobe's quarterly security updates. In total, there are 40 vulnerabilities being addressed today - many of them rated as critical and exposing systems to potential remote exploits.
Microsoft Patch Tuesday
A Microsoft spokesperson emailed the following "Today, as part of its routine monthly security update cycle, Microsoft is releasing 11 security bulletins to address 25 vulnerabilities: five rated Critical, five rated Important and one rated Moderate. This month's release affects Windows, Microsoft Office, and Microsoft Exchange. Additionally, the Malicious Software Removal Tool (MSRT) was updated to include Win32/Magania."
Qualys CTO Wolfgang Kandek noted in his blog post "Microsoft's patch release for April contains 11 bulletins covering 25 vulnerabilities. The bulletins address a wide array of operating systems and software packages, IT administrators with a good inventory of their installed base will have an easier time to evaluating which machines need patches."
"The critical Microsoft WinVerifyTrust signature validation vulnerability can be used to really enhance social engineering efforts," said Joshua Talbot, security intelligence manager, Symantec Security Response in an emailed statement. "Targeted attacks are popular and since social engineering plays such a large role in them, plan on seeing exploits developed for this vulnerability."
Talbot continued "It allows an attacker to fool Windows into thinking that a malicious program was created by a legitimate vendor. If a user begins to download an application and they see the Windows' notification telling them who created it, they might think twice before proceeding if it's from an unfamiliar source. This vulnerability allows an attacker to force Windows to report to the user that the application was created by any vendor the attacker chooses to impersonate."
Andrew Storms, director of security operations for nCircle offered this analysis "More movies and more malware: that's what we've got to look forward to on the Internet. Microsoft is patching critical bugs in Windows Media Player and Direct Show this month - both of these bugs lend themselves to online video malware. If you put these fixes together with Apple's recent patch of Quicktime, it's pretty obvious that attackers are finding a lot of victims through video."