Wednesday, August 25, 2010

Microsoft DLL Vulnerability

Yesterday Microsoft released a security advisory for a vulnerability in how Windows handles dynamic link libraries or DLLs. This is a vulnerability in the core of Windows that can also impact many applications running on Windows, so it's a pretty big concern.

If you are running a home computer on Windows, your best bet at protection is to disable the WebClient service. To do this right-click on your "My Computer" icon and choose "Manage", go to "Services and Applications" and choose "Services". Scroll down to "WebClient", right-click on it and select "Properties", change the startup type to "Disabled" and click "OK". Then stop the service if it is running (right click on it and choose "Stop".)

Note that if you are in an enterprise environment disabling the WebClient service may cause some applications to lose functionality (particularly applications like Microsoft SharePoint). If you are in such an environment, I advise you to contact your Helpdesk for assistance in how to address this issue.

Microsoft has no ETA for a fix for this issue, and as it is a core piece of Windows that affects how third-party applications interact with the OS, it may be a while before this can be addressed.

Monday, August 9, 2010

Microsoft Patch Day - Tuesday August 10

Microsoft will be releasing a record number of patches tomorrow, August 10th. A total of 14 bulletins will be released, addressing over 30 issues. Information on these patches can be found here.

So if you are a Windows user be aware that there will be a lot of updates recommended for your machine tomorrow. As always, I recommend that when this many patches come out at once, it's best to wait a bit before updating your machine, just to make sure there aren't any problems or compatibility issues with your software. If you want to do this you can turn off Automatic Updates from your control panel, just be sure to remember to turn it back on once you've installed the patches!

Thursday, August 5, 2010

Critical Microsoft Patch - Out of Band

I'm a little late on this one, however it's a critical patch for a vulnerability that is being widely exploited, so I figured I should post about it anyway.

Microsoft released an out of band patch to address a security vulnerability this Tuesday. This patch affects all versions of Windows and should be applied immediately.

So, if you're a Windows user run that Windows Update ASAP!