Microsoft Black Tuesday - December 2006 - Michael Sutton's Blog -
Microsoft Black Tuesday - December 2006

December looked a lot like November in terms of the volume and type of vulnerabilities patched by Microsoft. The seven security bulletins released today included a total of eleven vulnerabilities with the following breakdown for maximum severity:

  • 5 Critical
  • 5 Important
  • 1 Moderate

This month's bulletins included patches for two public vulnerabilities for which exploit code is already available. More importantly, Microsoft admits to being aware of at least targeted exploitation for CVE-2006-4704. The following publicly known issues received patches:

It appears that bulletin MS06-078 was actually a late addition due to the emergence of proof of concept exploit code in the past few days.

This month's bulletins did not address the following two Microsoft Word file format vulnerabilities. While Microsoft has acknowledged the vulnerabilities and the fact that they are being used in targeted attacks, they have not set a release date for patches.

Below is a cheat sheet for all 11 vulnerabilities.

[UPDATE 12/13/2006] Dave Aitel kindly corrected me to note that a private exploit is available for the SNMP vulnerability (MS06-074) as detailed below.

Enjoy!

- michael

 

Bulletin

Title

MS06-072





Script Error Handling Memory Corruption Vulnerability
CVE-2006-5579
Critical
Discovered By: Jakob Balle and Carsten Eiram of Secunia Research
Public: No
Exploited: No

MS06-072






DHTML Script Function Memory Corruption Vulnerability
CVE-2006-5581
Critical
Discovered By: Sam Thomas, working with TippingPoint and the Zero Day Initiative
Public: No
Exploited: No
Advisory: http://www.zerodayinitiative.com/advisories/ZDI-06-048.html

MS06-072





TIF Folder Information Disclosure Vulnerability
CVE-2006-5578
Important
Discovered By: Yorick Koster of ITsec Security Services
Public: No
Exploited: No

MS06-072  




TIF Folder Information Disclosure Vulnerability
CVE-2006-5577
Moderate
Public: No
Exploited: No

MS06-073







WMI Object Broker Vulnerability
CVE-2006-4704
Critical

Exploit: ie_createobject.pm
Discovered By: TippingPoint and the Zero Day Initiative
Public: Yes
Exploited: Yes
Advisory: http://www.zerodayinitiative.com/advisories/ZDI-06-047.html

MS06-074








SNMP Memory Corruption Vulnerability
CVE-2006-5583
Important
Exploit: A private exploit is available via the Immunity Inc. Partners Program
Discovered By:
            Kostya Kortchinsky of Immunity, Inc.
            Clement Seguy of the European Aeronautic Defence and Space Company
Public: No
Exploited: No

MS06-075



File Manifest Corruption Vulnerability
CVE-2006-5585
Important
Public: No

MS06-076




Windows Address Book Contact Record Vulnerability
CVE-2006-2386
Important
Public: No
Exploited: No

MS06-077





RIS Writable Path Vulnerability
CVE-2006-5584
Important
Discovered By: Nicolas Ruff
Public: No
Exploited: No

MS06-078




Windows Media Format ASF Parsing Vulnerability
CVE-2006-4702
Critical
Public: No
Exploited: No

MS06-078





Windows Media Format ASX Parsing Vulnerability
CVE-2006-6134
Critical
Exploit: 21247.asx
Public: Yes
Exploited: No

 


Posted 12-12-2006 6:26 PM by erik.peterson