|
Feature:
Microsoft Security Releases Bulletins – why should I heed them?
Microsoft Security Release Bulletins (MSRBs) are different from standard update releases, although updates often include MSRBs. Updates include bug fixes, where MSRBs are about someone else compromising your PC from the outside. Typically, MSRBs are issued monthly and come in four flavors – Critical, Important, Moderate and Low.
- Critical - If you don’t implement this, your machine could be compromised AND be responsible for compromising others.
- Important - Your machine and your personal data could be compromised.
- Moderate - If your machine and security are not set up properly, it could be compromised.
- Low - Your machine might be compromised, but it is either unlikely or will have minimal affect.
For the majority of average users, any Critical or Important release must be installed to maintain security. For business users, ALL security releases are important in order to be as safe as possible from compromise.
The recent MSRB (MS06-040) was published “out of band,” meaning Microsoft felt it was critical enough to release between monthly MSRBs. That means if you don’t install this, you WILL suffer. It affects all supported releases of Windows, so if you have Windows XP SP2 or SP3, XP professional 64-bit (any release), Windows Server 2003 (any release, including x64), installing this update is critical.
For Windows Vista and Windows Server 2008 systems, Microsoft has labeled this patch “Important,” but don’t take it lightly. Install the update.
Microsoft’s wording on this issue is, “This security update resolves a privately reported vulnerability in the Server service. The vulnerability could allow remote code execution if an affected system received a specially crafted RPC request.”
This means that another PC can send a request to your system to run software on your PC without your permission and without your knowledge, therefore turning your system into a zombie, either running software that sends your information to someone else and/or sending itself out to other PCs for the same purpose.
In the past, I have seen computers that were very busy processing illegal credit card transactions. These PCs were confiscated by Federal authorities as evidence of crimes, and were returned at a later date.
Included with these MSRBs are warnings of side affect found when installing the patches. Therefore, make sure you read ALL of each MSRB before installing the software. There may be procedures to run or other patches to install before installing the one you are considering.
For more information about Plait Solutions, provider of computer solutions for home owners and small businesses, call Sid Plait at 678.520.6176, go to www.plaitsolutions.com or visit Sid’s blog at blog.plaitsolutions.com.
|