Patch ‘n’ Patch per Microsoft!
Nel corso del giorno delle patch, Microsoft ha rilasciato, per il mese di Giugno, sei aggiornamenti che vanno a risolvere complessivamente 15 falle di sicurezza, 12 delle quali considerate critiche.
La vulnerabilità di sicurezza riguarda il pacchetto Secure Channel di Windows che implementa i protocolli di autenticazione standard Secure Sockets Layer (SSL) e Transport Layer Security (TLS). Qualora l’utente dovesse collegarsi con una pagina web espressamente studiata per sfruttare la lacuna di sicurezza, potrebbe vedere eseguito – a propria insaputa – sul sistema in uso, codice dannoso. Sui sistemi Windows Server 2003 e Windows 2000 il problema dovrebbe ridursi ad un crash del browser o del sistema. Patch critica.
Le vulnerabilità complessivamente risolte sono, in questo caso, quattro e consentono di mettersi al riparo dai rischi derivanti dall’apertura di messaggi di posta contenenti codice nocivo. Patch "critica"
La vulnerabilità riguarda le API Win32 del sistema operativo e potrebbe consentire ad un malintenzionato di eseguire, da remoto, codice nocivo qualora l’API risultasse in uso da parte dell’applicazione utilizzata per far leva sul problema di sicurezza. Patch critica.
Microsoft ha rilasciato anche un nuovo aggiornamento per il suo "Strumento di rimozione malware" (download)
—
Bollettino ufficiale:
Bulletin Information
====================The security bulletins for this month are as follows, in order of
severity:Critical Security Bulletins
===========================MS07-031 – Vulnerability in the Windows Schannel Security Package
Could Allow Remote Code Execution (935840)– Affected Software:
– Microsoft Windows 2000 Service Pack 4
– Windows XP Service Pack 2
– Windows XP Professional x64 Edition
– Windows XP Professional x64 Edition Service Pack 2
– Windows Server 2003 Service Pack 1
– Windows Server 2003 Service Pack 2
– Windows Server 2003 with SP1 for Itanium-based Systems
– Windows Server 2003 with SP2 for Itanium-based Systems
– Windows Server 2003 x64 Edition
– Windows Server 2003 x64 Edition Service Pack 2– Impact: Remote Code Execution
– Version Number: 1.0MS07-033 – Cumulative Security Update for Internet Explorer (933566)
– Affected Software:
– Microsoft Windows 2000 Service Pack 4
– Windows XP Service Pack 2
– Windows XP Professional x64 Edition
– Windows XP Professional x64 Edition Service Pack 2
– Windows Server 2003 Service Pack 1
– Windows Server 2003 Service Pack 2
– Windows Server 2003 with SP1 for Itanium-based Systems
– Windows Server 2003 with SP2 for Itanium-based Systems
– Windows Server 2003 x64 Edition
– Windows Server 2003 x64 Edition Service Pack 2
– Windows Vista
– Windows Vista x64 Edition– Impact: Remote Code Execution
– Version Number: 1.0MS07-034 – Cumulative Security Update for Outlook Express and
Windows Mail (929123)– Affected Software:
– Windows XP Service Pack 2
– Windows XP Professional x64 Edition
– Windows XP Professional x64 Edition Service Pack 2
– Windows Server 2003 Service Pack 1
– Windows Server 2003 Service Pack 2
– Windows Server 2003 with SP1 for Itanium-based Systems
– Windows Server 2003 with SP2 for Itanium-based Systems
– Windows Server 2003 x64 Edition
– Windows Server 2003 x64 Edition Service Pack 2
– Windows Vista
– Windows Vista x64 Edition– Impact: Remote Code Execution
– Version Number: 1.0MS07-035 – Vulnerability in Win32 API Could Allow Remote Code
Execution (935839)– Affected Software:
– Microsoft Windows 2000 Service Pack 4
– Windows XP Service Pack 2
– Windows XP Professional x64 Edition
– Windows XP Professional x64 Edition Service Pack 2
– Windows Server 2003 Service Pack 1
– Windows Server 2003 Service Pack 2
– Windows Server 2003 with SP1 for Itanium-based Systems
– Windows Server 2003 with SP2 for Itanium-based Systems
– Windows Server 2003 x64 Edition
– Windows Server 2003 x64 Edition Service Pack 2– Impact: Remote Code Execution
– Version Number: 1.0Important Security Bulletins
============================MS07-030 – Vulnerabilities in Microsoft Visio Could Allow Remote
Code Execution (927051)– Affected Software:
– Microsoft Visio 2002 Service Pack 2
– Microsoft Visio 2003 Service Pack 2– Impact: Remote Code Execution
– Version Number: 1.0Moderate Security Bulletins
===========================MS07-032 – Vulnerability in Windows Vista Could Allow Information
Disclosure (931213)– Affected Software:
– Windows Vista
– Windows Vista x64 Edition– Impact: Information Disclosure
– Version Number: 1.0Other Information
=================Microsoft Windows Malicious Software Removal Tool:
==================================================
Microsoft has released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center.Note that this tool is not distributed using Software Update Services (SUS).
Non-Security, High-Priority Updates on MU, WU, WSUS and SUS:
============================================================
For this month:* Microsoft has released seven non-security,
high-priority updates on Microsoft Update (MU) and
Windows Server Update Services (WSUS).* Microsoft has not released any non-security,
high-priority updates for Windows on Windows Update (WU) and
Software Update Services (SUS).