Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Tenable Blog

Subscribe

Microsoft Patch Tuesday Roundup - December 2010 - "Bad Santa" Edition

MadSanta-SM.jpg

Attackers have been very naughty, IT departments have been mostly nice and Microsoft has fulfilled the role of “Bad Santa”. This holiday season, Microsoft has filled your stockings with 17 security bulletins fixing 40 vulnerabilities. But where does that leave us?

What Else Could You Say?

Note: The word "could" appears in the title of all 17 security bulletins this month

I could say a lot of things about this month's Microsoft Patch Tuesday release. I could say that you should apply patches (except that my boss hates the word “should”). I could say that despite all of the patches released, there are still most likely to be 0-day exploits for several unpublished vulnerabilities. I could also say that your organization needs a solid patch management program. I could say, well, you get the point. After more than a year of writing up each one of the Microsoft Security bulletins, there's a lot I could say. The fact remains that several trends continue in the Microsoft "Black Tuesday" madness:


  • Various individuals and organizations continue to tell you how to prioritize the application of patches

  • Microsoft will continue to downplay the extent of the vulnerabilities being released and patched

  • Organizations will take time to patch all of the vulnerabilities released each month

The big question remains, what is the best course of action? Who am I to say, but I will take a stab at what I believe you can do to protect yourselves:

  • Be Bold - Let’s face it, hundreds, if not thousands, of computers are running vulnerable software on your network right now. Big vendors such as Microsoft, Adobe and Oracle are patching their products as fast as they can. You have to balance availability with risk and get the patches out as soon as possible. Most patches, including most of those provided by Microsoft this month, require a reboot. I believe what many will realize is that business operations will be just fine if you push some patches out and schedule reboots. More than ever before, attackers are focusing on the desktop and preying on victims browsing the web, chatting on Facebook and clicking on links from instant messages. A little inconvenience for your users may cause them to complain, but this has little to do with the bottom line and keeping the business going.
  • Be Thorough - Rebooting all the systems in your environment is no easy task, and neither is keeping up with all the machines coming and going on your network. Applying patches is no longer enough; you need to verify that patches are installed and activated. There are several situations where this is not such a cut and dry issue. For example, multiple versions of a software package could be installed on the system, and only the most recent version receives a patch.
  • Realize Your Perimeter Doesn't Exist - While firewalls and antivirus software may buy you time, they don't fix the problems of insecurity on your systems. The sense of "perimeter" we once had should have completely faded away at this point. Between wireless technology, users browsing the web, reading email, using Twitter, USB drives and smartphones, there is little you can do to prevent attackers from getting on the "inside" of the network. Secure your network as such, from the inside out. This means identifying your data and putting layers of defense around it that take into account that evil bad guys may gain access to the surrounding network.
  • Pretend You Are Running Windows 2000 SP1 - Okay, I'm joking here a bit. However, I believe this to be a valuable lesson. Just for fun, pretend that you can't apply patches to your hosts. What now? What kinds of protections would you put in place to protect your assets? This will look different for many organizations, but I bet you can use your skills to come up with some pretty effective and even creative methods of defense against attackers without applying patches. Now take all that creative genius and go implement some of it on your network. You can also do this exercise with your other lines of defense and start to build a more comprehensive and resilient defensive strategy for your organization.

To further aid in your efforts to evaluate the dangers of the vulnerabilities addressed by Microsoft Patch Tuesday, Tenable's Research team has published plugins for each of the security bulletins issued this month:

Conclusion

The above list is light on details, as it’s much of the same thing we've seen before. I believe I've covered all of the hidden treasures inside Microsoft Patch Tuesday, and hopefully worked to raise awareness of the dangers, patch prioritization, Microsoft's language used to describe severity and more. As such, future posts on Microsoft Patch Tuesday will likely simply announce the patches and plugins and make an interesting point or two. Hopefully by now, our readers have learned about all the pitfalls associated with Microsoft Patch Tuesday.

If ever you wish to go back and read all of the details associated with our Microsoft Patch Tuesday coverage, you can access them using the blog category "Microsoft Patch Tuesday".

Resources

Microsoft 2010 Patch Tuesday Chronicles from the Tenable Security Blog:

Related Articles

Cybersecurity News You Can Use

Enter your email and never miss timely alerts and security guidance from the experts at Tenable.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Try Tenable Web App Scanning

Enjoy full access to our latest web application scanning offering designed for modern applications as part of the Tenable One Exposure Management platform. Safely scan your entire online portfolio for vulnerabilities with a high degree of accuracy without heavy manual effort or disruption to critical web applications. Sign up now.

Your Tenable Web App Scanning trial also includes Tenable Vulnerability Management and Tenable Lumin.

Buy Tenable Web App Scanning

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

5 FQDNs

$3,578

Buy Now

Try Tenable Lumin

Visualize and explore your exposure management, track risk reduction over time and benchmark against your peers with Tenable Lumin.

Your Tenable Lumin trial also includes Tenable Vulnerability Management and Tenable Web App Scanning.

Buy Tenable Lumin

Contact a Sales Representative to see how Tenable Lumin can help you gain insight across your entire organization and manage cyber risk.

Try Tenable Nessus Professional Free

FREE FOR 7 DAYS

Tenable Nessus is the most comprehensive vulnerability scanner on the market today.

NEW - Tenable Nessus Expert
Now Available

Nessus Expert adds even more features, including external attack surface scanning, and the ability to add domains and scan cloud infrastructure. Click here to Try Nessus Expert.

Fill out the form below to continue with a Nessus Pro Trial.

Buy Tenable Nessus Professional

Tenable Nessus is the most comprehensive vulnerability scanner on the market today. Tenable Nessus Professional will help automate the vulnerability scanning process, save time in your compliance cycles and allow you to engage your IT team.

Buy a multi-year license and save. Add Advanced Support for access to phone, community and chat support 24 hours a day, 365 days a year.

Select Your License

Buy a multi-year license and save.

Add Support and Training

Try Tenable Nessus Expert Free

FREE FOR 7 DAYS

Built for the modern attack surface, Nessus Expert enables you to see more and protect your organization from vulnerabilities from IT to the cloud.

Already have Tenable Nessus Professional?
Upgrade to Nessus Expert free for 7 days.

Buy Tenable Nessus Expert

Built for the modern attack surface, Nessus Expert enables you to see more and protect your organization from vulnerabilities from IT to the cloud.

Select Your License

Buy a multi-year license and save more.

Add Support and Training