{"id":3238,"date":"2011-12-15T08:41:44","date_gmt":"2011-12-15T08:41:44","guid":{"rendered":"https:\/\/www.darknet.org.uk\/?p=3238"},"modified":"2015-09-09T19:37:02","modified_gmt":"2015-09-09T11:37:02","slug":"no-beast-fix-from-microsoft-in-december-patch-tuesday-but-they-fixed-duqu-bug","status":"publish","type":"post","link":"https:\/\/www.darknet.org.uk\/2011\/12\/no-beast-fix-from-microsoft-in-december-patch-tuesday-but-they-fixed-duqu-bug\/","title":{"rendered":"No BEAST Fix From Microsoft In December Patch Tuesday – But They Fixed Duqu Bug"},"content":{"rendered":"

It looks like Microsoft<\/a> originally had a patch for the BEAST vulnerability, but for some reason they have withdrawn it for the December Patch Tuesday.<\/p>\n

It’s a pretty bumper crop of patches though with 13 bulletins and 19 vulnerabilities fixed, the highest profile one being a patch for the zero-day vulnerability exploited by Duqu.<\/p>\n

The pulling of the BEAST patch is good in a way though I guess, it shows that Microsoft are doing comprehensive compatibility testing to ensure the patches don’t cause any problems (including with 3rd party software).<\/p>\n

Microsoft released 13 security bulletins addressing 19 vulnerabilities overnight, as part of a bumper final Patch Tuesday of the year.<\/p>\n

Highlight of the baker’s dozen is a patch for the the zero-day vulnerability exploited by Duqu (sibling of Stuxnet) worm back in October. Fixing the underlying flaw exploited by Duqu involves the resolution of a problem in how Windows kernel mode driver handles TrueType font files.<\/p>\n

Aside from this critical update the batch includes an update to address a critical flaw n Windows Media Player. A cumulative security update of ActiveX kill bits is covered by the third, and final, critical update this month. The other ten bulletins address less severe (important) flaws in Windows, IE and Office. Altogether its a desktop-heavy patch batch, as you can see from Microsoft’s summary here.<\/p>\n

Microsoft originally promised 14 bulletins for the December edition of Patch Tuesday but one has been pulled, probably for quality control reasons. The original anticipated 14th bulletin was for the BEAST attack, but did not make it in time for the holidays due to a last minute software incompatibility uncovered during third party testing, security services firm Qualys reports. The absence of this fix means that Microsoft has issued a grand total of 99 bulletins this year, one less than the ton up that might have resulted in adverse headlines.<\/p><\/blockquote>\n

Both BEAST and Duqu are pretty nasty malware<\/a>, I’d guess seen as though they’ve already fixed the BEAST problem – they just need to work on compatibility issues – that we’ll definitely be seeing the patch rolled out in the January Patch Tuesday<\/a>.<\/p>\n

It’s good to see a bunch of important patches rolled out pre Christmas though as there’s always an influx of malware, scams, spams and phishing<\/a> attempts around this period (trying to leverage on people’s good will I guess).<\/p>\n