Thursday, 15 December 2011

Microsoft Patch Tuesday Compatibility Report by ChangeBASE - 13th December 2011

With this December Microsoft Patch Tuesday update, we see a relatively large set of updates. In total there are 13 Microsoft Security Updates; 3 with the rating of Critical and 10 with the rating of Important. This is a relatively large update from Microsoft and the potential impact for the updates is likely to be moderate.

As part of the Patch Tuesday Security Update analysis performed by the ChangeBASE team, we have seen moderate cause for potential compatibility issues.

Given the nature of the changes and updates included in each of these patches, most systems will require a reboot to successfully implement any and all of the patches and updates released in this December Patch Tuesday release cycle.


Sample Results
Here is a sample of the results for one application and a summary of the Patch Tuesday results for one of our AOK Sample databases:

MS11-091: Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution.

MS11-093: Vulnerabilities in OLE Could Allow Remote Code Execution.


And here is a sample AOK Summary report for a sample database where the AOK Patch Impact team has run the latest Microsoft Updates against a small application portfolio:


Testing Summary
MS11-087
Vulnerability in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (2639417)
MS11-088
Vulnerability in Microsoft Office IME (Chinese) Could Allow Elevation of Privilege
MS11-089
Vulnerability in Microsoft Office Could Allow Remote Code Execution (2590602)
MS11-090
Cumulative Security Update of ActiveX Kill Bits (2618451)
MS11-091
Vulnerabilities in Microsoft Publisher Could Allow Remote Code Execution (2607702)
MS11-092
Vulnerability in Windows Media Could Allow Remote Code Execution (2648048)
MS11-093
Vulnerability in OLE Could Allow Remote Code Execution (2624667)
MS11-094
Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution (2639142)
MS11-095
Vulnerability in Active Directory Could Allow Remote Code Execution (2640045)
MS11-096
Vulnerability in Microsoft Excel Could Allow Remote Code Execution (2640241)
MS11-097
Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2620712)
MS11-098
Vulnerability in Windows Kernel Could Allow Elevation of Privilege (2633171)
MS11-099
Cumulative Security















Security Update Detailed Summary
MS11-087
Vulnerability in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (2639417)
Description
This security update resolves a publicly disclosed vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a specially crafted document or visits a malicious Web page that embeds TrueType font files.
Payload
Win32k.sys
Impact
Critical - Remote Code Execution
MS11-088
Vulnerability in Microsoft Office IME (Chinese) Could Allow Elevation of Privilege
Description
This security update resolves a privately reported vulnerability in Microsoft Office IME (Chinese). The vulnerability could allow elevation of privilege if a logged-on user performed specific actions on a system where an affected version of the Microsoft Pinyin (MSPY) Input Method Editor (IME) for Simplified Chinese is installed. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full administrative rights. Only implementations of Microsoft Pinyin IME 2010 are affected by this vulnerability. Other versions of Simplified Chinese IME and other implementations of IME are not affected.
Payload
Not Defined
Impact
Important - Elevation of Privilege
MS11-089
Vulnerability in Microsoft Office Could Allow Remote Code Execution (2590602)
Description
This security update resolves a privately reported vulnerability in Microsoft Office. The vulnerability could allow remote code execution if a user opens a specially crafted Word file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Payload
Not Defined
Impact
Important - Remote Code Execution
MS11-090
Cumulative Security Update of ActiveX Kill Bits (2618451)
Description
This security update resolves a privately reported vulnerability in Microsoft software. The vulnerability could allow remote code execution if a user views a specially crafted Web page that uses a specific binary behavior in Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. This update also includes kill bits for four third-party ActiveX controls.
Payload
Not Defined
Impact
Critical - Remote Code Execution
MS11-091
Vulnerabilities in Microsoft Publisher Could Allow Remote Code Execution (2607702)
Description
This security update resolves one publicly disclosed vulnerability and three privately reported vulnerabilities in Microsoft Office. The most severe vulnerabilities could allow remote code execution if a user opens a specially crafted Publisher file. An attacker who successfully exploited any of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Payload
Mspub.exe, Prtf9.dll, Ptxt9.dll, Pubconv.dll
Impact
Important - Remote Code Execution
MS11-092
Vulnerability in Windows Media Could Allow Remote Code Execution (2648048)
Description
This security update resolves a privately reported vulnerability in Windows Media Player and Windows Media Center. The vulnerability could allow remote code execution if a user opens a specially crafted Microsoft Digital Video Recording (.dvr-ms) file. In all cases, a user cannot be forced to open the file; for an attack to be successful, a user must be convinced to do so.
Payload
Encdec.dll
Impact
Critical - Remote Code Execution
MS11-093
Vulnerability in OLE Could Allow Remote Code Execution (2624667)
Description
The vulnerability could allow remote code execution if a user opens a file that contains a specially crafted OLE object. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Payload
Ole32.dll
Impact
Important - Remote Code Execution
MS11-094
Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution (2639142)
Description
This security update resolves privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially crafted PowerPoint file. An attacker who successfully exploited either of the vulnerabilities could take complete control of an affected system. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Payload
Not Defined
Impact
Important - Remote Code Execution
MS11-095
Vulnerability in Active Directory Could Allow Remote Code Execution (2640045)
Description
This security update resolves a privately reported vulnerability in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS). The vulnerability could allow remote code execution if an attacker logs on to an Active Directory domain and runs a specially crafted application. To exploit this vulnerability, an attacker would first need to acquire credentials to log on to an Active Directory domain.
Payload
Adamdsa.dll
Impact
Important - Remote Code Execution
MS11-096
Vulnerability in Microsoft Excel Could Allow Remote Code Execution (2640241)
Description
This security update resolves a privately reported vulnerability in Microsoft Office. The vulnerability could allow remote code execution if a user opens a specially crafted Excel file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Installing and configuring Office File Validation (OFV) to prevent the opening of suspicious files blocks the attack vectors for exploiting the vulnerabilities described in CVE-2011-3403.
Payload
Excel.exe
Impact
Important - Remote Code Execution
MS11-097
Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2620712)
Description
This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application designed to send a device event message to a higher-integrity process. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability.
Payload
Csrsrv.dll
Impact
Important - Elevation of Privilege
MS11-098
Vulnerability in Windows Kernel Could Allow Elevation of Privilege (2633171)
Description
This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application designed to exploit the vulnerability. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.
Payload
Ntkrnlmp.exe, Ntkrnlpa.exe, Ntkrpamp.exe, Ntoskrnl.exe, Mpsyschk.dll
Impact
Important - Elevation of Privilege
MS11-099
Cumulative Security
Description
This security update resolves three privately reported vulnerabilities in Internet Explorer. The most severe vulnerability could allow remote code execution if a user opens a legitimate HyperText Markup Language (HTML) file that is located in the same directory as a specially crafted dynamic link library (DLL) file.
Payload
Not Defined
Impact
Important - Remote Code Execution

*All results are based on a ChangeBASE Application Compatibility Lab’s test portfolio of over 1,000 applications.

Wednesday, 30 November 2011

Linkbait: November 2011

Here's this month's Industry Newsletter by my ChangeBASE colleague, Carl Bennett.

Packaging News 
A new tool from Microsoft, the Program Install and Uninstall Troubleshooting Tool, attempts to resolve MSI install issues.
Active Setup introduction on InstallShield blog.
A nice roundup of Program Compatibility Assistant’s features care of Chris Jackson.
All regsvr32 does is Load¬Library, Get¬Proc¬Address, and then calls the function. Why can’t you query if it was successful?
InstallShield 2012 SP1 is out.
More news on Symantec’s retirement of Wise.
Examine the contents of MSU and CAB Microsoft Update installs.
Lessmsi, the tool for quickly extracting files from MSIs now has shell integration.
Microsoft Deployment Toolkit 2012 Beta 2 is available.

Platform News
The experience of installing Windows 8 has been improved.
Windows 8 defrag has new options.
Synaptics have unveiled a great-looking mouse driver for Windows 8.
Make your Windows 7 desktop more Autumnal with a theme.

Office News
Microsoft Office Starter 2010 is a free version of Word and Excel 2010. It also allows you to create a portable version which can be run off a USB drive.
Office 15 beta is rumoured to be out in January.
How to extract customisation information from an Office 2010 MSP.
How Office may look in the future.

Virtualisation News
A walkthrough of sequencing and deploying in Server App-V.
Server App-V has a nifty commandline for binding processes into the same bubble.
ThinApp 4.7 has been released with integration to the Horizon Application Manager. Learn about ThinApp on your smartphone.

Browser and Web News
Go to google and search for the words “do a barrel roll” or “tilt” (seems to work better in Firefox than IE for me). Oh what fun!
IE10 has the first browser-based implementation of auto-correct.
I like this ad for Google Analytics with Nick Mohammed.

Mobile News
A mobile phone in 1922.



Tuesday, 18 October 2011

Another day, another coup for ChangeBASE


So here we are at VMware Europe 2011, Copenhagen and very nice it is too.
The show is busy and we’re looking forward to hearing what VMware has coming down the track in 2012 and beyond and just where the world of virtualisation will take us and how it will sit along side the rapid growth of cloud based applications and services.
But for ChangeBASE it’s another show and yet another development. Today we announce the launch of our VMware ThinApp plug in for AOK VReady-It. This plug-in enables organisations to convert their MSI applications to a virtualised ThinApp application and ensure that it is ready for deployment on the VMware platform.
You can read the release here.
As with all of the ChangeBASE plug-ins for AOK VReady-It,  the ThinApp plugin enables;
  • ·         Bulk conversion of applications to ThinApp
  • ·         Dramatic reduction in the time it takes to manually convert applications to a virtualised platform
  • ·         Conversion of legacy applications that may not migrate to new operating systems
  • ·         Ability to create a single executable with no dependencies
  • ·         Significant savings of time and resource
We’ve got it on stand (Stand 137) so why not pop along to say hello and see AOK VReady-It in action!

Friday, 14 October 2011

Linkbait: October 2011


My colleague Carl has done it again and delivered some great links to some good reading on our industry and ChangeBase.


Migration news
A powerpoint presentation called “Life after Windows XP” containing some great arguments for upgrading to Windows 7.
Windows 7 has just passed XP as most widely used OS
The Microsoft performance team explain the advantage of 64bit Windows
Converter Technology look at whether it is worth skipping Windows7 and going straight to Windows8. Microsoft say 10 years is enough, just upgrade now will you?
Chris Jackson posted a link to his chat with Emily and Greg.

Packaging News
Symantec have announced that they will discontinue Wise. In my opinion they have never understood the asset that they had.  It’s not just a piece of software but the fuel for an entire industry.  It is still used by a vast proportion of all packaging teams.  Aaaagh I am so angry, upset and disappointed right now.
Can you pass the Windows 7 Deployment exam? I’ll admit that I scraped a pass by 1%
After reporting last month that AppX may succeed, an article on why AppX Just Might Fail.
A Microsoft mindmap download is available on the topic of deployment
A ThinApp guide to the Taskbar, and Start Menu Pinning gives you an insight into their virtualisation process.
The unattend file allows you to change some standard windows folders but not Program Files.

Windows 8 News
The Building Windows 8 Blog is a very well-written guide to the design philosophy behind the new features.  Learn about how the start menu has evolved into the start screen.
Translations are being sought for the new charm and app terminologies
Desktop gadgets are being axed, but you never used them anyway

Obituary Corner
Dennis Ritchie, inventor of the C programming language, co-author of the famous book on it, and co-creator of the Unix operating system, has died ;

Mobile News
The new 64Gb iPhone 4S has been launched.  Apple say “It’s a good phone”
The Samsung Galaxy SII has won every award going and has sold 10 Million

Cloud News
Windows 8 can seamlessly integrate with skydrive

Technology News
Microsoft have slipped to third most valuable tech company behind IBM and Apple
I want a new computer, the best one consumes 10Mw although the old ones look nice.
Our partners Converter Technologies write about broken links in office documents.

Browser News
Internet Explorer 9 on Windows 7 Passes 30% Share in the US
Firefox 7 has shipped, version 8 is now in beta
What is The Internet and How does it Work?

Enjoy and have a listen of the Chris Jackson pod-cast. Chris is always both entertaining and educating.

Thursday, 6 October 2011

AOK Browse-It for Firefox Launched!


They say that you should try to learn something new every day. And I have to say that within my world at ChangeBASE that is usually the case. I’m always astounded at the things I learn, see and experience on my travels and when working with partners and customers.

One thing that has really stood out for me this year has been the increase of multi-browser deployment within organisations. It reinforces the fact that the growth of web applications and use of the internet is rapidly enveloping our daily working lives. It also provisions a more versatile approach to the IT environment which is always a good thing.

Today we launched AOK browse-It for Firefox. Much has been written about Mozilla Firefox and in both my experience and via evidence of the usage analysis, Firefox is the second most popular browser to Internet Explorer holding over26%  market share. This is why our development team decided to develop the AOK Browse-It plug-in alongside the IE9 plug-in for our award winning solution.

The AOK Browse-It for Firefox plug-in ensures Firefox compatibility for web applications. It quickly and accurately identifies the six key areas of compatibility including;

  • Proprietary Internet Explorer calls and functions
  • Non-standard HTML functions and event calls
  • Non-compliant CSS functions and calls
  • DOM model quirks and non supported functions
  • JavaScript standards compliance
  • Plug-in manager component and configuration compatibility


So have a look, I believe that the multi-browser environment is here to stay and Firefox plays a major role in that.