November 08, 2011
Microsoft Security Bulletin: November 8
Advisory Overview

November 8, 2011 - Qualys® Vulnerability R&D Lab has released new vulnerability checks in QualysGuard® to protect organizations against 4 vulnerabilities present in Microsoft Windows that were announced today. Customers can immediately audit their networks for these and other new vulnerabilities by accessing their QualysGuard subscription. Please visit our podcast page for patch tuesday prioritization and summary.

Vulnerability Details

Microsoft has released 4 security patches to fix newly discovered flaws in Microsoft Windows. Qualys has released the following checks for these new vulnerabilities:


Microsoft Windows TCP/IP Remote Code Execution Vulnerabilities (MS11-083)
SEVERITY: Urgent Urgent-5 5
QUALYS ID: 90753
VENDOR REFERENCE: MS11-083
CVE REFERENCE: CVE-2011-2013
CVSS SCORES: Base 7.5 | Temporal 5.5
THREAT: TCP/IP is a set of networking protocols that are widely used on the Internet. TCP/IP provides communication across interconnected networks of computers that have diverse hardware architectures and that run various operating systems.

A remote code execution vulnerability exists in the Windows TCP/IP stack when processing a continuous flow of crafted UDP packets, resulting in an integer overflow.

Affected Software:
Microsoft Windows Vista
Windows Server 2008
Windows 7
Windows Server 2008 R2

This security update is rated Critical.

IMPACT: Successfully exploiting this vulnerability might allow a remote attacker to take complete control of the affected system.
SOLUTION: Patch:

Following are links for downloading patches to fix the vulnerabilities:

Windows Vista Service Pack 2

Windows Vista x64 Edition Service Pack 2

Windows Server 2008 for 32-bit Systems Service Pack 2

Windows Server 2008 for x64-based Systems Service Pack 2

Windows Server 2008 for Itanium-based Systems Service Pack 2

Windows 7 for 32-bit Systems and Windows 7 for 32-bit Systems Service Pack 1

Windows 7 for x64-based Systems and Windows 7 for x64-based Systems Service Pack 1

Windows Server 2008 R2 for x64-based Systems and Windows Server 2008 R2 for x64-based Systems Service Pack 1

Windows Server 2008 R2 for Itanium-based Systems and Windows Server 2008 R2 for Itanium-based Systems Service Pack 1

Refer to Microsoft Security Bulletin MS11-083 for further details.


Microsoft Windows Kernel-Mode Drivers Denial of Service Vulnerability (MS11-084)
SEVERITY: Serious Serious-3 3
QUALYS ID: 90751
VENDOR REFERENCE: MS11-084
CVE REFERENCE: CVE-2011-2004
CVSS SCORES: Base 9.7 | Temporal 7.6
THREAT: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow denial of service if a user opens a specially crafted TrueType font file as an email attachment or navigates to a network share or WebDAV location containing a specially crafted TrueType font file.

Affected Software:
Windows 7
Windows 2008 R2

This security update is rated Moderate.

IMPACT: An attacker that successfully exploits this vulnerability could cause the target system to stop responding and restart.
SOLUTION: Patch:

Following are links for downloading patches to fix the vulnerabilities:

Windows 7 for 32-bit Systems and Windows 7 for 32-bit Systems Service Pack 1

Windows 7 for x64-based Systems and Windows 7 for x64-based Systems Service Pack 1

Windows Server 2008 R2 for x64-based Systems and Windows Server 2008 R2 for x64-based Systems Service Pack 1

Windows Server 2008 R2 for Itanium-based Systems and Windows Server 2008 R2 for Itanium-based Systems Service Pack 1

Refer to Microsoft Security Bulletin MS11-084 for further details.


Microsoft Windows Mail and Windows Meeting Space Remote Code Execution Vulnerability (MS11-085)
SEVERITY: Critical Critical-4 4
QUALYS ID: 90752
VENDOR REFERENCE: MS11-085
CVE REFERENCE: CVE-2011-2016
CVSS SCORES: Base 9.3 | Temporal 7.3
THREAT: Windows Mail (formerly Outlook Express) is an online communication tool for use with Windows and Windows Meeting Space gives the ability to share documents, programs, or desktop with other people whose computers are running Windows Vista.

A remote code execution vulnerability exists in the way that Windows Mail and Windows Meeting Space handle the loading of DLL files (CVE-2011-2016).

Affected Software:
Windows Vista
Windows Server 2008
Windows 7
Windows Server 2008 R2

This security update is rated Important for all supported editions of Windows Vista; is rated Moderate for all supported editions of Windows Server 2008; and is rated Low for all supported editions of Windows 7 and Windows Server 2008 R2.

IMPACT: Successfully exploiting this vulnerability might allow a remote attacker to execute arbitrary code.
SOLUTION: Patch:

Following are links for downloading patches to fix the vulnerabilities:

Windows Vista Service Pack 2

Windows Vista x64 Edition Service Pack 2

Windows Server 2008 for 32-bit Systems Service Pack 2

Windows Server 2008 for x64-based Systems Service Pack 2

Windows Server 2008 for Itanium-based Systems Service Pack 2

Windows 7 for 32-bit Systems and Windows 7 for 32-bit Systems Service Pack 1

Windows 7 for x64-based Systems and Windows 7 for x64-based Systems Service Pack 1

Windows Server 2008 R2 for x64-based Systems and Windows Server 2008 R2 for x64-based Systems Service Pack 1

Windows Server 2008 R2 for Itanium-based Systems and Windows Server 2008 R2 for Itanium-based Systems Service Pack 1

Refer to Microsoft Security Bulletin MS11-085 for further details.


Microsoft Active Directory Elevation of Privilege Vulnerability (MS11-086)
SEVERITY: Urgent Urgent-5 5
QUALYS ID: 90754
VENDOR REFERENCE: MS11-086
CVE REFERENCE: CVE-2011-2014
CVSS SCORES: Base 9.3 | Temporal 6.9
THREAT: Active Directory Services contains an extensible and scalable set of services that enables you to efficiently manage corporate identities, credentials, information protection, and system and application settings.

An elevation of privilege vulnerability exists in Active Directory when Active Directory is configured to use LDAPS and fails to validate the revocation status of an SSL certificate against the CRL associated with the domain account. This allows a certificate to be accepted as valid even after it has been revoked by the certification authority (CA). (CVE-2011-2014)

Affected Software:
Windows XP Service Pack 3 (Active Directory Application Mode (ADAM))
Windows XP Professional x64 Edition Service Pack 2 (Active Directory Application Mode (ADAM))
Windows Server 2003 Service Pack 2 (Active Directory, Active Directory Application Mode (ADAM))
Windows Server 2003 x64 Edition Service Pack 2 (Active Directory, Active Directory Application Mode (ADAM))
Windows Vista Service Pack 2 (Active Directory Lightweight Directory Service (AD LDS))
Windows Vista x64 Edition Service Pack 2(Active Directory Lightweight Directory Service (AD LDS))
Windows Server 2008 for 32-bit Systems Service Pack 2 (Active Directory and Active Directory Lightweight Directory Service (AD LDS))
Windows Server 2008 for x64-based Systems Service Pack 2 (Active Directory and Active Directory Lightweight Directory Service (AD LDS))
Windows 7 for 32-bit Systems (Active Directory and Active Directory Lightweight Directory Service (AD LDS))
Windows 7 for 32-bit Systems Service Pack 1 (Active Directory and Active Directory Lightweight Directory Service (AD LDS))
Windows 7 for x64-based Systems (Active Directory and Active Directory Lightweight Directory Service (AD LDS))
Windows 7 for x64-based Systems Service Pack 1 (Active Directory and Active Directory Lightweight Directory Service (AD LDS))
Windows Server 2008 R2 for x64-based Systems (Active Directory and Active Directory Lightweight Directory Service (AD LDS))
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Active Directory and Active Directory Lightweight Directory Service (AD LDS))

This security update is rated Important.

IMPACT: An attacker who successfully exploits this vulnerability could obtain access to network resources or run code under the privileges of a specific authorized user. If the user has administrator privileges, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
SOLUTION: Patch:

Following are links for downloading patches to fix the vulnerabilities:

Windows XP Service Pack 3 (Active Directory Application Mode (ADAM))

Windows XP Professional x64 Edition Service Pack 2 (Active Directory Application Mode (ADAM))

Windows Server 2003 Service Pack 2 (Active Directory)

Windows Server 2003 Service Pack 2 (Active Directory Application Mode )

Windows Server 2003 x64 Edition Service Pack 2 (Active Directory)

Windows Server 2003 x64 Edition Service Pack 2 (Active Directory Application Mode )

Windows Server 2003 with SP2 for Itanium-based Systems (Active Directory)

Windows Vista Service Pack 2 (Active Directory Lightweight Directory Service (AD LDS))

Windows Vista x64 Edition Service Pack 2 (Active Directory Lightweight Directory Service (AD LDS))

Windows Server 2008 for 32-bit Systems Service Pack 2 (Active Directory and Active Directory Lightweight Directory Service (AD LDS))

Windows Server 2008 for x64-based Systems Service Pack 2 (Active Directory and Active Directory Lightweight Directory Service (AD LDS))

Windows 7 for 32-bit Systems (Active Directory Lightweight Directory Service (AD LDS))

Windows 7 for 32-bit Systems Service Pack 1 (Active Directory Lightweight Directory Service (AD LDS))

Windows 7 for x64-based Systems (Active Directory Lightweight Directory Service (AD LDS))

Windows 7 for x64-based Systems Service Pack 1 (Active Directory Lightweight Directory Service (AD LDS))

Windows Server 2008 R2 for x64-based Systems (Active Directory and Active Directory Lightweight Directory Service (AD LDS))

For a complete list of patch download links, please refer to Microsoft Security Bulletin MS11-086.

This new vulnerability check is included in Qualys vulnerability signatures 1.28.266-3. Each QualysGuard account is automatically updated with the latest vulnerability signatures as they become available. To view the vulnerability signature version in your account, from the QualysGuard HOME menu, select the Account Info tab.

SELECTIVE SCAN INSTRUCTIONS USING QUALYSGUARD:

To perform a selective vulnerability scan, configure a scan profile to use the following options:

  1. Ensure access to TCP ports 135 and 139 are available.
  2. Enable Windows Authentication (specify Authentication Records).
  3. Enable the following Qualys IDs:
    • 90753
    • 90751
    • 90752
    • 90754
  4. If you would like the scan to return the Windows Hostname, also include QID 82044 and ensure access to UDP port 137 is available.
  5. If you would like to be notified if QualysGuard is unable to logon to a host (if Authentication fails), also include QID 105015.

In addition, prior to running a scan for these new vulnerabilities, you can estimate your exposure to these new threats by running the Risk Matrix Report, available from the QualysGuard HOME page.


Technical Support
For more information, customers may contact Qualys Technical Support directly at support@qualys.com or by telephone toll free at:
US: 1 866.801.6161 | EMEA: 33 1 44.17.00.41 | UK: +44 1753 872102
About QualysGuard
QualysGuard is an on-demand security audit service delivered over the web that enables organizations to effectively manage their vulnerabilities and maintain control over their network security with centralized reports, verified remedies, and full remediation workflow capabilities with trouble tickets. QualysGuard provides comprehensive reports on vulnerabilities including severity levels, time to fix estimates and impact on business, plus trend analysis on security issues. By continuously and proactively monitoring all network access points, QualysGuard dramatically reduces security managers' time researching, scanning and fixing network exposures and enables companies to eliminate network vulnerabilities before they can be exploited.

Access for QualysGuard customers: https://qualysguard.qualys.com

Free trial of QualysGuard service: http://www.qualys.com/forms/trials/qualysguard_trial/