Windows Secrets

Subscribers: Sign in

Enter your e-mail address to get a free subscription.
We guarantee your privacy
Skip to content
  • Home
  • Newsletter Archives
    • Current
    • LangaList Plus
    • Patch Watch
    • Wacky Web Week
    • Security Baseline
  • WinDeals
  • E-Books
  • Lounge
  • Polls
  • About us
    • Refunds
    • Privacy Policy
    • Advertise
  • Contact
  • Your Account
    • Upgrade
    • Preferences
    • Bonus Download
    • Unsubscribe
Home>Patch Watch>Microsoft releases a taxing week of patches

Microsoft releases a taxing week of patches

Posted on April 15, 2010 by Susan Bradley in Patch Watch
Tweet

Susan Bradley 1 Microsoft releases a taxing week of patches By Susan Bradley

Digitally signed software is a system designed to build trust in the applications you install on a PC.

Most of us don’t think twice about installing digitally-signed software, but we should — now that malware has made this system less trustworthy.


MS10-019 (978601, 979309)
Signed software may install more than advertised

In my first Patch Watch item, I’m showcasing a trust exploit, not a browser exploit. PC users regularly install digitally-signed software, trusting that it’s clean, safe, and what the vendor intended to provide. Microsoft security bulletin MS10-019 includes two updates to fix problems in Windows Authenticode and Windows Cabinet File Viewer. Without these two patches, it’s possible for you to unwittingly install infected software that bears a seemingly genuine digital signature.

While that sounds extremely scary, I’ll remind you that all too often we merrily install unsigned apps. We’ve all seen the warning shown in Figure 1. I myself recently added an unsigned Microsoft hotfix to my Windows 7 machine. The truth is, Microsoft tech support regularly sends fixes by e-mail and includes patch installers with no digital signatures. Almost without fail, I simply go ahead and install the hotfix.

Patch 2010 04 15Fig1 Microsoft releases a taxing week of patches
Figure 1. An example of unsigned files from Microsoft.

The affected systems that are patched by MS10-019 are those running:

  • Windows XP SP2 and SP3
  • XP Pro x64 Edition SP2
  • Vista, Vista SP1 and SP2, 32- and 64-bit versions
  • Windows 7, 32- and 64-bit versions
  • Windows Server 2008 and Server 2008 R2
► What to do: Don’t panic — just install the two patches in security bulletin MS10-019, as you do other critical updates from Microsoft. Do be aware that hackers have found ways to spoof signed files. Don’t immediately trust downloads from unfamiliar sites just because they have a digital signature.

MS10-026 (977816) and MS10-027 (979402)
Patch now to protect against drive-by downloads

I’m discussing security bulletins MS10-026 and MS10-027 together in this item. Although the two bulletins patch different flaws, they address similar attacks on Microsoft MPEG codecs and Media Player — the now-familiar remote-code execution problem.

This article is part of our paid content. Subscribe.

Already a paid subscriber? Click here to login.

Related posts:

  1. Microsoft releases an emergency patch for IE
  2. More than just two patches this week
  3. Security patches, service releases and updates
  4. Patches for IE should be top priority this week
  5. Microsoft releases Virtual PC 2007
= Paid content

All Windows Secrets articles posted on 2010-04-15:

  • Introduction New admins and mods join us in revealing secrets
  • Top Story Run your PC from afar — securely and easily
  • Lounge Life Formatting in Word results in major headaches
  • Wacky Web Week Bandleader plays more than symphonic music
  • LangaList Plus Run multiple antivirus applications on one PC
  • In the Wild Living without Adobe Flash Reader or Sun’s Java
  • Patch Watch Microsoft releases a taxing week of patches
  •  Show all articles on a single page
Susan Bradley

About Susan Bradley

Susan Bradley is a Small Business Server and Security MVP, a title awarded by Microsoft to independent experts who do not work for the company. She's also a partner in a California CPA firm.
View all posts by Susan Bradley →

WinDeals

WinDeals offers subscribers regular discounts — of up to 50 percent off — on software and technology products. Read moreยป

View current deals
Top-scoring articles in the past 12 months
  • Leaving long cookie trails throughout the Web 5.00
  • Windows-like security for Android devices 5.00
  • Win7′s no-reformat, nondestructive reinstall 4.56
  • LizaMoon infection: a blow-by-blow account 4.46
  • RPV: Win7′s least-known data-protection system 4.35
  • Recovery: the last step in total data security 4.31
  • The sorry tale of the (un)Secure Sockets Layer 4.30
  • Time for a .NET update we can’t ignore 4.30
  • Getting the most from Windows Search — Part 1 4.25
  • Revising printing habits saves money and trees 4.25
  • Upgrades end in erratic, partial hangs 4.25
  • Get wired performance from your Wi-Fi network 4.24
  • Caution: Bumps in the road to IPv6 4.23
  • Patch Watch adds problem-patch update chart 4.23
  • ZeuS Trojan reinvents itself as bots rock on 4.22
  • Pros and cons of a ‘keyfile’ password 4.21
  • April brings showers of browser patches 4.20
  • Readers comment on the LizaMoon infection story 4.20
  • Office 2007 gets its final service pack 4.19
  • Putting Registry-/system-cleanup apps to the test 4.19
  • The advanced system-recover toolkit 4.18
  • One year and 99 security bulletins later 4.18
  • Don’t pay for software you don’t need — Part 3 4.17
  • What to do when Windows refuses to boot 4.17
  • Make the most of Windows 7′s Libraries 4.16
  • Keeping you up to date: say no to .NET — again 4.16
  • Internet Explorer gets another round of patches 4.15
  • Vacation’s over; it’s a big round of patches 4.15
  • Big-time Wi-Fi security for the small office 4.14
  • Office File Validation patch leads to problems 4.14
Connect with us Follow us on Twitter Connect with us on Facebook View our RSS Feeds
  • Home|
  • Newsletter|
  • About Windows Secrets|
  • Advertise with us|
  • Unsubscribe|
  • Sitemap|
  • Affiliates|
Trademarks: Microsoft and Windows are registered trademarks of Microsoft Corporation. The Windows Secrets series of books is published by Wiley Publishing Inc. The Windows Secrets Newsletter, WindowsSecrets.com, WinFind, Windows Gizmos, Security Baseline, Patch Watch, Perimeter Scan, Wacky Web Week, the Logo Design (W, S or road, and Star), and the slogan Everything Microsoft Forgot to Mention all are trademarks and service marks of iNET Interactive. All other marks are the trademarks or service marks of their respective owners.
iNET Interactive Copyright © 2011 iNET Interactive.
All rights reserved.
Terms of Use  |  Privacy Policy
Internet Services
  • Web Hosting Talk
  • HostingCon
  • Hosting Catalog
  • Host Voice
Web Development
  • Hot Scripts
  • DB Forums
Digital Marketing
  • ABestWeb
  • Search Marketing Standard
  • PayPerClickUniverse
  • SEMCompare
Consumer Tech
  • Windows Secrets
  • Overclockers
  • Mac Forums

Learn more about
advertising opportunities across the iNET Interactive Network.

LiquidWeb