This morning I received one of the Windows Secret Newsletters from Brian Livingston that I subscribe to. I always find them informative. The one this morning was a special one, titled Microsoft posts emergency defense for new attack.
Brian Livingston points to an article from Susan Bradley, by the same title. Here she talks about a rare out-of-cycle patch (not their usual Wednesdays update) from Microsoft emphasizing the real risk of a Web worm - "A remote-code exploit that could spread rapidly like the 2003 MSBlaster worm is putting all versions of Windows at risk."
I quote "With little warning, Microsoft released yesterday an unscheduled or "out-of-cycle" patch for a highly critical vulnerability that affects all versions of Windows. Security bulletin MS08-067 (patch 958644) was posted to warn of a remote-code attack that could spread wildly across the Internet."
She also reports that "Many AV vendors have already issued definition updates that protect against this attack. Your AV program, however, may not protect you completely even if your AV definitions are up-to-date. Early reports indicate that there are already nine different strains of viruses trying to take advantage of this vulnerability. We can expect more to come, so even the best AV application may not be able to update fast enough."
Susan recommends that people immediately install the patch to protect their system from vulnerability in the Server service. And strongly urges you to download and install the patch manually.
Another great suggestion is that you Restart your PC before installing any patch to verify that your computer is bootable. "Then be sure to Restart again after installing the patch, so the patched binaries completely replace the vulnerable components."
After I read this email I checked the MSFT page for Security Update for Windows Vista Here is where you can click on the Download button to download it directly.
I also checked my Available Updates and sure enough, Update KB958644 was there since yesterday. I went ahead and installed it. Even though the update itself didn't take long, I must warn you - the actual Restarting process did take quite a while. I was having breakfast while all this was going on, and I started thinking that perhaps I might have to press the button and turn it off, when I finally got the last screen. Then after that, it still took a little while for Update 3 of 3 to finish and give me the Welcome page. (I do have a few photo editing programs, plus Trend MicroAV which take a long time to load, though.)
Here is a Snip of part of the article where it shows the different OS that are affected by this worm:
(Sorry, it's not too clear, and those are not clickable links.) The links are in the article from Windows Secrets. Here's where you can subscribe to receive the Newsletters, if you want.
Here's another article from The Register, that talks about the emergency update too.
I wanted to share this important information with you all because we're all interested in doing our best to keep our computers safe. Stay informed to stay safe!
:) Thanks for reading.
ps - Susan Brandley recently received an MVP (Most Valuable Professional) award from Microsoft for her knowledge in the areas of Small Business Servers and network security.
Sign In
Register
Help



MultiQuote

