Microsoft’s March “Patch Tuesday” update is taking a slightly different approach than in previous months. Released today, this month’s Patch Tuesday update includes six security advisories — and for the most critical flaws, Microsoft is providing both a patch and a ‘Fix It’ update.
The critical flaws are addressed in the MS12-020 bulletin, detailing vulnerabilities in Remote Desktop Protocol (RDP). The flaws could have potentially enabled an attacker to execute arbitrary remote code.
“The patch actually fixes the problem, and the Fix It implements the workaround,” Wolfgang Kandek, CTO of security firm Qualys, told InternetNews.com.
Kandek explained that the Fix It update enables Network Layer Authentication (NLA) protocol, which mitigates the risk that the MS12-020 bulletin warns about. The Fix It also does not require a system reboot, which is required by the full patch.
“The Fix It does not cure the root cause,” Amol Sarwate, Director of Vulnerability Labs at Qualys, told InternetNews.com. “It does enough to make sure that attackers can not trigger the vulnerable condition.”
Microsoft does not normally release both a Fix It update as well as a full patch at the same time. Typically, Fix It updates have been released as a quick workaround to protect users until a full patch is made available.
“In this case, Microsoft wants users to use NLA,” Kandek said. “Microsoft is trying to steer people to review their policies around remote desktop and some users might still have a legacy setting, that is only really necessary if they use older versions that don’t support NLA.”
Sarwate noted that by releasing the Fix It update as well as the full patch, Microsoft is giving users the chance to mitigate the immediate risk, without the need to immediately do a full reboot.