Recently in Deployment diary Category

ChangeBASE Microsoft Patch Tuesday Report 11th October 2011

| 1 Comment
| More

Application Compatibility Update

By: Greg Lambert

 

Executive Summary

With this October Microsoft Patch Tuesday update, we see again a relatively small set of updates. In total there are eight Microsoft Security Updates, 2 with the rating of Critical and 6 with the rating of Important. This is a moderate update from Microsoft and the potential impact for the updates is minor.

 

As part of the Patch Tuesday Security Update analysis performed by the ChangeBASE AOK team, we have seen very little cause for potential compatibility issues.

 

Given the nature of the changes and updates included in each of these patches, most systems will require a reboot to successfully implement any and all of the patches and updates released in this October Patch Tuesday release cycle.

 

Sample Results

MS10-028: Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution.

patch tuesday oct 1.png

 

Testing Summary

 

MS11-075

Vulnerability in Microsoft Active Accessibility Could Allow Remote Code Execution (2623699)

MS11-076

Vulnerability in Windows Media Center Could Allow Remote Code Execution (2604926)

MS11-077

Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (2567053)

MS11-078

Vulnerability in .NET Framework and Microsoft Silverlight Could Allow Remote Code Execution (2604930)

MS11-079

Vulnerabilities in Microsoft Forefront Unified Access Gateway Could Cause Remote Code Execution (2544641)

MS11-080

Vulnerability in Ancillary Function Driver Could Allow Elevation of Privilege (2592799)

MS11-081

Cumulative Security Update for Internet Explorer (2586448)

MS11-082

Vulnerabilities in Host Integration Server Could Allow Denial of Service (2607670)

 

patch tuesday oct 2.jpg















































 

Security Update Detailed Summary

 

MS11-075

Vulnerability in Microsoft Active Accessibility Could Allow Remote Code Execution (2623699)

Description

This security update resolves a privately reported vulnerability in the Microsoft Active Accessibility component. The vulnerability could allow remote code execution if an attacker convinces a user to open a legitimate file that is located in the same network directory as a specially crafted dynamic link library (DLL) file. Then, while opening the legitimate file, the Microsoft Active Accessibility component could attempt to load the DLL file and execute any code it contained. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by a vulnerable application.

Payload

Oleacc.dll, Oleaccrc.dll, Uiautomationcore.dll, Wow_oleacc.dll, Wow_oleaccrc.dll, Wow_uiautomationcore.dll

Impact

Important - Remote Code Execution

 

MS11-076

Vulnerability in Windows Media Center Could Allow Remote Code Execution (2604926)

Description

This security update resolves a publicly disclosed vulnerability in Windows Media Center. The vulnerability could allow remote code execution if an attacker convinces a user to open a legitimate file that is located in the same network directory as a specially crafted dynamic link library (DLL) file. Then, while opening the legitimate file, Windows Media Center could attempt to load the DLL file and execute any code it contained. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a legitimate file.

Payload

Mpeg2data.ax, Msdvbnp.ax, Msnp.ax, Psisdecd.dll, Psisrndr.ax

Impact

Important - Remote Code Execution

 

MS11-077

Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (2567053)

Description

This security update resolves four privately reported vulnerabilities in Microsoft Windows. The most severe of these vulnerabilities could allow remote code execution if a user opens a specially crafted font file (such as a .fon file) in a network share, a UNC or WebDAV location, or an e-mail attachment. For a remote attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open the specially crafted font file, or open the file as an e-mail attachment.

Payload

Win32k.sys, W32ksign.dll

Impact

Important - Remote Code Execution

 

MS11-078

Vulnerability in .NET Framework and Microsoft Silverlight Could Allow Remote Code Execution (2604930)

Description

This security update resolves a privately reported vulnerability in Microsoft .NET Framework and Microsoft Silverlight. The vulnerability could allow remote code execution on a client system if a user views a specially crafted Web page using a Web browser that can run XAML Browser Applications (XBAPs) or Silverlight applications. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. The vulnerability could also allow remote code execution on a server system running IIS, if that server allows processing ASP.NET pages and an attacker succeeds in uploading a specially crafted ASP.NET page to that server and then executes the page, as could be the case in a Web hosting scenario. This vulnerability could also be used by Windows .NET applications to bypass Code Access Security (CAS) restrictions.

Payload

 N/A

Impact

Critical - Remote Code Execution

 

MS11-079

Vulnerabilities in Microsoft Forefront Unified Access Gateway Could Cause Remote Code Execution (2544641)

Description

This security update resolves five privately reported vulnerabilities in Forefront Unified Access Gateway (UAG). The most severe of these vulnerabilities could allow remote code execution if a user visits an affected Web site using a specially crafted URL. However, an attacker would have no way to force users to visit such a Web site. Instead, an attacker would have to persuade users to visit the Web site, typically by getting them to click a link in an e-mail message or Instant Messenger message that takes users to the attacker's Web site.

Payload

Adfs.internalerror.inc, Adfs.internalsite.de_de.xml, Adfs.internalsite.en_us.xml, Adfs.internalsite.es_es.xml, Adfs.internalsite.fr_fr.xml, Adfs.internalsite.it_it.xml, Adfs.internalsite.ja_jp.xml, Adfs.internalsite.ko_kr.xml, Adfs.internalsite.pt_br.xml, Adfs.internalsite.ru_ru.xml, Adfs.internalsite.zh_cn.xml, Adfs.internalsite.zh_tw.xml, Internalerror.inc, Internalsite.de_de.xml, Internalsite.en_us.xml, Internalsite.es_es.xml, Internalsite.fr_fr.xml, Internalsite.it_it.xml, Internalsite.ja_jp.xml, Internalsite.ko_kr.xml, Internalsite.pt_br.xml, Internalsite.ru_ru.xml, Internalsite.zh_cn.xml, Internalsite.zh_tw.xml, Mobileinternalsite.microsoft.uag.mobilebrowsing.dll, Monitor.default.asp, Monitor.exceltable.asp, Monitor.sessionparameters.asp, Signurl.asp, Whlfilter.dll, Whlfiltsecureremote.dll

Impact

Important - Remote Code Execution

 

MS11-080

Vulnerability in Ancillary Function Driver Could Allow Elevation of Privilege (2592799)

Description

This security update resolves a privately reported vulnerability in the Microsoft Windows Ancillary Function Driver (AFD). The vulnerability could allow elevation of privilege if an attacker logs on to a user's system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit the vulnerability.

Payload

Afd.sys

Impact

Important - Elevation of Privilege

 

MS11-081

Cumulative Security Update for Internet Explorer (2586448)

Description

This security update resolves eight privately reported vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Payload

 N/A

Impact

Critical - Remote Code Execution

 

MS11-082

Vulnerabilities in Host Integration Server Could Allow Denial of Service (2607670)

Description

This security update resolves two publicly disclosed vulnerabilities in Host Integration Server. The vulnerabilities could allow denial of service if a remote attacker sends specially crafted network packets to a Host Integration Server listening on UDP port 1478 or TCP ports 1477 and 1478. Firewall best practices and standard default firewall configurations can help protect networks from attacks that originate outside the enterprise perimeter. Best practices recommend that systems that are connected to the Internet have a minimal number of ports exposed. In this case, the Host Integration Server ports should be blocked from the Internet.

Payload

 N/A

Impact

Important - Denial of Service

 

*All results are based on an AOK Application Compatibility Lab's test portfolio of over 1,000 applications.

September 13th Microsoft Patch Tuesday Application Compatibility Report by ChangeBASE

| No Comments
| More

Application Compatibility Update

By: Greg Lambert

 

Executive Summary

With this September Microsoft Patch Tuesday update, we see again a relatively small set of updates in comparison to the lists of updates released by Microsoft in the previous months. In total there are five Microsoft Security Updates with the rating of Important. This is a minor update from Microsoft and the potential impact for the updates is likely to be moderate.

 

As part of the Patch Tuesday Security Update analysis performed by the ChangeBASE AOK team, we have seen very little cause for potential compatibility issues.

 

Given the nature of the changes and updates included in each of these patches, most systems will require a reboot to successfully implement any and all of the patches and updates released in this September Patch Tuesday release cycle.

 

Sample Results 1: MS11-070 Vulnerability in WINS Could Allow Elevation of Privilege

 patch sept 1.png

 

Sample Results 2: MS11-073 Vulnerabilities in Microsoft Office Could Allow Remote Code Execution

 

patch sept 2.png

 

Testing Summary

 

MS11-070

Vulnerability in WINS Could Allow Elevation of Privilege (2571621)

MS11-071

Vulnerability in Windows Components Could Allow Remote Code Execution (2570947)

MS11-072

Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2587505)

MS11-073

Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2587634)

MS11-074

Vulnerabilities in Microsoft SharePoint Could Allow Elevation of Privilege (2451858)

 

Sample Results 3: AOK Summary Report Sample from a small database

patch sept 3.png

AOK Patch Summary Results

Patch sept 4.PNG

Security Update Detailed Summary

 

MS11-070

Vulnerability in WINS Could Allow Elevation of Privilege (2571621)

Description

This security update resolves a privately reported vulnerability in the Windows Internet Name Service (WINS). The vulnerability could allow elevation of privilege if a user received a specially crafted WINS replication packet on an affected system running the WINS service. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability.

Payload

W03a3409.dll, Wins.exe, Winsevnt.dll, Ww03a3409.dll, Wwins.exe, Wwinsevnt.dll

Impact

Important - Elevation of Privilege

 

MS11-071

Vulnerability in Windows Components Could Allow Remote Code Execution (2570947)

Description

This security update resolves a publicly disclosed vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a legitimate rich text format file (.rtf), text file (.txt), or Word document (.doc) that is located in the same network directory as a specially crafted dynamic link library (DLL) file. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Payload

Imjpapi.dll

Impact

Important - Remote Code Execution

 

MS11-072

Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2587505)

Description

This security update resolves five privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Installing and configuring Office File Validation (OFV) to prevent the opening of suspicious files blocks the attack vectors for exploiting the vulnerabilities described in CVE-2011-1986 and CVE-2011-1987.

Payload

Excel.exe

Impact

Important - Remote Code Execution

 

MS11-073

Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2587634)

Description

This security update resolves two privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially crafted Office file or if a user opens a legitimate Office file that is located in the same network directory as a specially crafted library file. An attacker who successfully exploited either of the vulnerabilities could gain the same user rights as the logged on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Payload

Ietag.dll, Mso.dll

Impact

Important - Remote Code Execution

 

MS11-074

Vulnerabilities in Microsoft SharePoint Could Allow Elevation of Privilege (2451858)

Description

This security update resolves five privately reported vulnerabilities and one publicly disclosed vulnerability in Microsoft SharePoint and Windows SharePoint Services. The most severe vulnerabilities could allow elevation of privilege if a user clicked on a specially crafted URL or visited a specially crafted Web site. For the most severe vulnerabilities, Internet Explorer 8 and Internet Explorer 9 users browsing to a SharePoint site in the Internet Zone are at a reduced risk because, by default, the XSS Filter in Internet Explorer 8 and Internet Explorer 9 helps to block the attacks in the Internet Zone. The XSS Filter in Internet Explorer 8 and Internet Explorer 9, however, is not enabled by default in the Intranet Zone.

Payload

Groove.exe, Groovedocumentsharetool.dll, Grooveutil.dll, Groovewebplatformservices.dll, Groovewebservices.dll

Impact

Important - Elevation of Privilege

 

*All results are based on an AOK Application Compatibility Lab's test portfolio of over 1,000 applications.

 

 

Microsoft Patch Tuesday Update - 14th December 2010

| No Comments
| More

With this week's Microsoft Patch Tuesday update, we see the largest collection of updates ever delivered by Microsoft in a single Patch Tuesday release with 17 updates having the following rating; 2 Critical, 14 Important and 1 Moderate. Aside from the significant number of Security and Application updates with this Patch Tuesday release cycle, we see a moderate number of issues affecting a small number of applications. The ChangeBASE team recommends a particular focus on the Microsoft Security Update MS10-106 as it raised a significant number of issues on the AOK sample server platform portfolio.

Here is a sample of the results for one application and a summary of the Patch Tuesday results for one of our AOK Sample databases:


MS10-105 Vulnerabilities in Microsoft Office Graphics Filters Could Allow for Remote Code Execution
Patch Tuesday - image 1.JPG


And here is a sample AOK Summary report for a sample database where the AOK Patch Impact team has run the latest Microsoft Updates against a small application portfolio:


Patch Tuesday - image 2.JPG


You can read a full analysis of the AOK Patch Impact Testing Summary here.




Microsoft Patch Tuesday - 12th October 2010

| No Comments
| More

Application Compatibility Update

With this Microsoft Patch Tuesday update, we see the largest collection of updates ever delivered by Microsoft in a single Patch Tuesday release. In total, there are 16 updates with the following rating; 2 Critical, 12 Important and 2 Moderate. Aside from the significant number of Security and Application updates with this Patch Tuesday release cycle, we also see a significant number of applications dependent on this large tranche of changes. The ChangeBase team recommends that the testing cycle for these particular releases is especially thorough due to application dependencies on almost all of the security patches included in this release. Given the nature of the changes and updates included in each of these patches, most systems will require a reboot to successfully implement any and all of the patches and updates released in this October Patch Tuesday release cycle.

Here is a sample of the results for one application and a summary of the Patch Tuesday results for one of our AOK Sample databases.

MS10-074: Vulnerability in Microsoft Foundation Classes Could Allow Remote Code Execution.

Patch Tuesday - image1.JPG

Testing Summary
Patch Tuesday - image2.JPG

Patch Tuesday - image3.JPG
Patch Tuesday - image4.JPG

Security Update - Detailed Summary
Patch Tuesday - image5.JPG

Patch Tuesday - image6.JPG

Patch Tuesday - image7.JPG

Patch Tuesday - image8.JPG

Patch Tuesday - image9.JPG

Patch Tuesday - image10.JPG

Patch Tuesday - image11.JPG

Patch Tuesday - image12.JPG

*All results are based on an AOK Application Compatibility Lab's test portfolio of over 1,000 applications.





Microsoft Patch Tuesday - 15th September 2010

| No Comments
| More

The month of September sees nine Security bulletin updates that tackle a total of 13 vulnerabilities for Windows, Microsoft Office and Internet Explorer. With these nine updates, we see four rated as Critical and the remaining five updates rated as Important. We have included a sample screen-shot from the ChangeBASE AOK Workbench application that depicts one of the issues raised by one these Microsoft patches:


MS10-0063: Vulnerability in Unicode Scripts Processor Could Allow Remote Code Execution 

Image1.JPG

Testing Summary

Image2.JPG


Image3.JPG


Security Update Detailed Summary

Image4.JPG

Image7.JPG

Image8.JPG

Image9.JPG

Image10.JPG



Microsoft Patch Tuesday - 10th August 2010

| No Comments
| More

With this Microsoft Patch Tuesday update, we have the largest release of security and application updates that the ChangeBASE team has dealt with. Nine of the updates rate as 'Critical' and the remaining six updates are rated as 'Important' - a very significant release by Microsoft standards.


As we have seen in many other Microsoft Patch Tuesday releases, all of these patches will require a system restart for both workstation and server environments.


We have also included a brief snap-shot image of some of the sample results from the AOK Workbench with a single application and Patch Impact Assessment result for MS10-053, the IE browser security update;

MS10-053: Cumulative Security Update for Internet Explorer:

August Patch Tuesday Update - image1.JPG

Testing Summary

MS10-046

Vulnerability in Windows Shell Could Allow Remote Code Execution (2286198)

MS10-049

Vulnerabilities in SChannel Could Allow Remote Code Execution (980436)

MS10-051

Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution (2079403)



MS10-052

Vulnerability in Microsoft MPEG Layer-3 Codecs Could Allow Remote Code Execution (2115168)

MS10-053

Cumulative Security Update for Internet Explorer (2183461)

MS10-054

Vulnerabilities in SMB Server Could Allow Remote Code Execution (982214)

MS10-055

Vulnerability in Cinepak Codec Could Allow Remote Code Execution (982665)

MS10-056

Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (2269638)

MS10-060

Vulnerabilities in the Microsoft .NET Common Language Runtime and in Microsoft Silverlight Could Allow Remote Code Execution (2265906)

MS10-047

Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (981852)

MS10-048

Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2160329)

MS10-050

Vulnerability in Windows Movie Maker Could Allow Remote Code Execution (981997)

MS10-057

Vulnerability in Microsoft Office Excel Could Allow Remote Code Execution (2269707)

MS10-058

Vulnerabilities in TCP/IP Could Allow Elevation of Privilege (978886)

MS10-059

Vulnerabilities in the Tracing Feature for Services Could Allow an Elevation of Privilege (982799)

August Patch Tuesday Update - image2.JPG
August Patch Tuesday Update - image3.JPG

Security Update: Detailed Summary

August Patch Tuesday Update - image4.JPG

August Patch Tuesday Update - image5.JPG

August Patch Tuesday Update - image6.JPG

August Patch Tuesday Update - image8.JPG

August Patch Tuesday Update - image9.JPG

August Patch Tuesday Update - image10.JPG

August Patch Tuesday Update - image11.JPG

August Patch Tuesday Update - image12.JPG
August Patch Tuesday Update - image13.JPG

*All results are based on an AOK Application Compatability Lab's test portfolio of over 1,000 applications.

Microsoft Patch Tuesday: 13th July 2010

| No Comments
| More

With this July Microsoft Patch Tuesday Security Update, we see a moderate number of security updates with 4 updates to Windows XP, Windows 7 and Office, including three updates rated as 'Critical' and one rated as 'Important'. Unfortunately, all patched released this month will most likely require a reboot of the target system. In addition, all of these Microsoft Security Updates relate to Remote Code Execution vulnerabilities.

The ChangeBase AOK Patch Impact team has updated the sample application database to now more than 2000 unique application packages. All of the applications in this large sample application portfolio are analysed for application level conflicts with Microsoft Security Updates and potential dependencies.

Based on the results of our AOK Application Compatibility Lab, only one of the July Patch Tuesday updates is likely to require significant application level testing;

·         MS10-044 Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege

We have included a brief snap-shot of some of the results from our AOK Software that demonstrates some of the potential impacts on the OSP application package with the following image:

Patch Tuesday1.JPG

In addition to this high level summary, we have also included a small sample of one of the AOK Summary reports from a smaller sample database;


Patch Tuesday2.JPG

Microsoft Patch Tuesday Update Testing Summary

MS10-042 Cumulative Security Update of ActiveX Kill Bits

MS10-043 Cumulative Security Update for Internet Explorer

MS10-044 Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege

MS10-045 Vulnerabilities in Microsoft SharePoint Could Allow Elevation of Privilege 


Patch Tuesday3.JPG


Security Update Detailed Summary

Patch Tuesday4.JPG

Patch Tuesday5.JPG

Patch Tuesday6.JPG 






Office 2007 Deployment: One Year On (Improvements on the deployment process)

| 1 Comment
| More

Hello again dear CW Blog readers, it's been almost a year since the initial series of posts describing a automated method of deploying Office 2007 via your KIX-Based logon scripts, complete with additional items of interest surrounding the customisation of the Office Ribbon itself to allow you to call your own programs or functions for easier use of the product itself.

Now you thought that would be it on the matter, but of course as with all things, there can be room for improving the process itself.

The KIX method we used before assumed that the user running the logon script was an administrator of the machine, and of course provided not a lot of feedback to the user in terms of what the process was doing at the time.

There was also the point of not enough redundancy within the script itself to take into account certain issues like disk space, and what about informing the end user that a certain part failed and they needed to inform their helpdesk as to what failed?

What about having the option of specifying what server to run the install from for multiple locations and packaging the office folder content to be copied to any server and know that all will be well?

Office 2007 Deployment: Results

| No Comments
| More

Now there has been some time between the script being created and tested, let's go through some of the results we had from the testing and what kind of issues did occur as a result of installing Office in this fashion.

Office 2007 Deployment: The Main Script Part 5

| 2 Comments
| More

And now we reach the point where we install those Ribbon customisations. Now last time, I left Part 4 of the Main Script entry with the question of what could make the install of the ribbon files stop in its tracks. And so to the continuation of the logon script which will shed light on the matter.

;************* Silent Install the Office Ribbon links to the Help files ************************
;running using VSTOInstaller from the Visual Studio Tools (locally based on user's workstations)

? "Running registry change to allow silent Office Ribbon install"
if $officeinstall <> "0" and $ribbonpresent = "1"
shell "Regedit /s
\\server\netLogon\OfficeRibbonInstall\newexceptions.reg"
 if @error = 0
 ? "Registry has been updated to allow silent Ribbon install."
 Else
 ? "Registry hasn't been updated. You may experience problems with the Ribbon Install"
 endif
endif

What is this? A registry change? Why do we need to alter the registry to achieve our goals?

Well it's down to Microsoft as it goes.

You see, Microsoft introduced some security measures with .net applications to make sure that the user is certain they want to install the program they have just executed. One of the options you have is adding a certificate to the install files, and having a corresponding certificate on the workstations.

Then only certified applications would install without the prompt and if they recieved a program of questionable origin, they are warned. A jolly good idea really, as you do want to make sure that only authorised programs are installed.

If you were to run the install program from the VSTO file you created, you would be presented with something like this:

 

ribboninstallverify.gifBasically if you're happy with the install to proceed, then click install. Easy to do, but the problem with this is that the installer would prompt the user during the install process when we call the relevant files and there's a chance they would not install it. We want to eliminate that from the process to make sure that the user doesn't have to do anything.

About this Archive

This page is a archive of recent entries in the Deployment diary category.

Database Notes and Queries is the previous category.

Evolutionary IT is the next category.

Find recent content on the main index or look in the archives to find all content.

Archives

Category Archives

 

-- Advertisement --