Last week was an odd one in Redmond. Between the ongoing Conficker situation, an unusually heavy Patch Tuesday, and some product announcements that raised more questions than they answered, Microsoft managed to dominate the security news cycle in ways that were not entirely flattering. Let us take it piece by piece.

Conficker: Still Here

April 1 came and went without the internet-ending catastrophe that the media had breathlessly predicted for Conficker's activation date. The worm did update itself, as expected, but the expected tsunami of malicious activity did not materialize. What did happen was considerably more interesting from a security operations perspective.

The Conficker Working Group - the consortium of security vendors, researchers, and domain registrars that formed to combat the worm - estimates that somewhere between 5 and 10 million machines remain infected. The worm's peer-to-peer update mechanism means it can receive new instructions without relying on the domain generation algorithm that the Working Group has been pre-empting. In practical terms, there is a botnet of staggering size sitting quietly on the internet, and the people who control it have not yet decided what to do with it.

For enterprises, the Conficker situation is a long-running test of patch management discipline. The worm exploits MS08-067, a vulnerability that Microsoft patched in October 2008 - six months ago. Every machine still infected with Conficker is a machine that has gone at least six months without receiving a critical security update. That is not a malware problem. That is an operational process failure.

Patch Tuesday: Eight Bulletins

As if Conficker were not enough to keep security teams busy, last Tuesday's patch release included eight security bulletins covering twenty vulnerabilities. Five of the bulletins were rated critical. The marquee item was a vulnerability in the Windows HTTP services stack that could allow remote code execution on servers running IIS. That one deserves immediate attention if you run Windows web servers.

The volume itself is not unprecedented - Microsoft has had larger patch releases - but the timing was notable. Releasing a heavy patch load while the industry is still dealing with Conficker cleanup creates a prioritization challenge for security operations teams. Do you focus on getting MS08-067 deployed to the remaining holdouts, or do you shift attention to the new critical vulnerabilities? The answer, of course, is both, but resource constraints make that easier said than done.

There is also the ongoing question of patch quality. Microsoft has had several instances in the past year where patches caused application compatibility issues or required re-release. The pressure to ship patches quickly sometimes conflicts with the need to test them thoroughly, and enterprises that have been burned by bad patches are understandably cautious about deployment speed.

Microsoft Security Essentials

The more curious news item was the announcement that Microsoft is developing a free consumer antivirus product, currently codenamed "Morro" and expected to ship as Microsoft Security Essentials later this year. This will replace the Windows Live OneCare product, which Microsoft is discontinuing.

The implications of this announcement depend on your perspective. Consumer advocates will welcome a free, built-in security baseline for Windows users who currently run no antivirus at all - and there are a lot of them. The antivirus vendor community is considerably less enthusiastic, since a free Microsoft product threatens the low end of their market.

From an enterprise perspective, the interesting question is whether Microsoft will eventually bundle similar capabilities into the server and enterprise client platforms. If basic malware protection becomes a default feature of the operating system, it changes the value proposition of third-party endpoint security suites and potentially reshapes the competitive dynamics of the endpoint protection market.

What It All Means

Taken together, last week painted a picture of a company grappling with the consequences of its own platform's ubiquity. Conficker exists because Windows is everywhere and patching at scale is hard. The heavy patch load exists because a platform that runs on a billion machines presents an enormous attack surface. And the antivirus announcement exists because Microsoft has concluded that it cannot rely on third parties to protect its own user base.

There is a certain irony in the world's largest software company being forced to give away security tools to address the security problems created by its own software. But irony does not pay the bills of the security teams who spent last week triaging patches and hunting for Conficker infections. They just want the week to be over.

It is Wednesday. So far so good.

SA
SecForAll Editorial
Security Analysis & Commentary
SecForAll covers enterprise security trends, policy, and technology for security professionals and decision-makers. Our analysis draws on industry research, vendor briefings, and hands-on evaluation of security products and standards.