Silicon Shecky

Infosec Practitioner

  • About
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Links
    • Infosec
      • Burbsec
      • Infosec Exchange Mastodon
      • Hacks4Pancakes Blog
      • Krebs On Security
      • Bleeping Computer
  • Archives

Connect

  • Bluesky
  • LinkedIn
  • Mastodon
  • RSS
  • Twitter

[footer_backtotop]

Copyright © 2025 ·Sixteen Nine Pro Theme · Genesis Framework by StudioPress · WordPress

March Patch Tuesday

March 10, 2009 By Michael Kavka Leave a Comment

So here it is, the second Tuesday of March and we all know what that means. Yep Microsoft Patch Tuesday! So lets ee what good old Microsoft has patched up for us this month.

The only Critical is a Windows Kernel update, which is patching a hole that, “could allow an attacker to take complete control of your computer if you view a website, email, or document that contains an evil graphic or picture,” according to Eric Schultze of Shavlik Technologies.

Now we all know that a hole in the kernel is bad, and the way this is made to sound this hole can be even worse than other kernel hole, but still I would recommend installing the patch in a test environment first if possible, or at least on a non-mission critical machine. Something about making changes to the Kernel always make me a little leary.

Then there is a series of 4 patches for DNS. Not surprisingly these are for lesser used holes along the Kaminsky DNS attack lines. Definitely get these installed especially with some of the odd ways some viruses seem to be showing up from spoofed DNS.

Finally a patch related to SSL spoofing. Again important, but like the DNS patches, not listed as critical.

Personally, all the patches seem to adress some very serious issues. How SSL and DNS spoofing are not thought of as critical for patching is beyond my comprehension though. At least Microsoft did patch them. Now where is the Excel patch for a major hole in that program?

Mike

Filed Under: Computers Tagged With: 2003, 2008, DNS, Microsoft, SBS, Security, Server, SSL, Vista, vulnerabilities, Windows, XP

RSS Taggart Institute Intel Feed

  • Microsoft: Windows 11 Media Creation Tool broken on Windows 10 PCs October 13, 2025 Sergiu Gatlan
  • What Happened When AI Came for Craft Beer October 13, 2025 Joseph Cox
  • Cybersecurity Awareness Month: 10 tips to Stay Safe Online that anyone can use October 13, 2025 jonmunshaw
  • UK fines 4chan over noncompliance with Online Safety Act October 13, 2025
  • China probes Qualcomm's Autotalks deal amid rising US trade tensions October 13, 2025 Joe Fay
  • Harvard investigating breach linked to Oracle zero-day exploit October 13, 2025 Lawrence Abrams
  • Ofcom fines 4chan £20K and counting for pretending UK's Online Safety Act doesn't exist October 13, 2025 Connor Jones
  • AI and the Future of American Politics October 13, 2025 Bruce Schneier
  • Dutch government puts Nexperia on a short leash over chip security fears October 13, 2025 Dan Robinson
  • The Coming AI Backlash October 13, 2025 Beatrice Magistro

Browse by tags

Active Directory Android Antivirus Apple Beta Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches Rants SBS SBS 2008 Security Security Patches Server SMB Software Support Surface TechEd Tweets Ubuntu Verizon Virus Vista vulnerabilities Windows Windows 7 Windows 8 XP