Header
1Vol 13-2   February 2013
2
Ekaru
Specializing in information technology outsourcing for small and medium businesses (1-50 Employees). "It's like having your own IT department"
  • Network Design
  • High Speed Internet
  • Computers & Software Network
  • Security Email & Web Hosting
  • Back-ups
  • Virus Protection & Recovery
  • Web Sites
  • Professional Service
www.ekaru.com

978-692-4200
866-go-ekaru


Welcome to this month's issue! The Technology Advisor provides technology advice, strategy, tips and trends to help you manage and grow your business!  Happy Valentines Day!

Tech Headlines
Here are some of the Tech headlines we're tracking:
  
Family Physicians lead in EHR Adoption - More that two thirds of family doctors had Electronic Health Records (EHR) in 2011 and the number is rising.   Read more at InformationWeek
  
Is your Ergonomic Desk Trying to Kill You? - The health benefits of sitting less are well established (I love my stand-up desk), but the addition of the treadmill poses some challenges!  Read More at MarketWatch 

  
This Kickstarter project is looking to charge up your phone by harnessing the power of hot and cold drinks - Charge your phone with a cold beer - pretty cool!  Read More on CNET 

 
The Best Activity Trackers for Fitness - I love my fitbit!  Read More at PC Magazine

 

The Taxman Cometh for Big Data-Driven Companies -  Interesting analysis as governments are looking for more tax revenue.   Read More on InformationWeek
  
Rackspace is one of the EPA's Top 20 Tech and Telecom Green Power Partners - Contratulations to Rackspace for their use of renewable energy.  This is where we host our mail servers in the cloud.   Read More at the Rackspace Blog
  
Ekaru Blog - Windows Anytime Upgrade  Do you have the "Home" version of the operating system and you need the "Professional" version?  Don't worry, the upgrade is easy!
Webinar - MA Data Security Law - Are you Compliant?

 

Do you want your laptop searched?The Massachusetts Data Security Law went into effect almost three years ago. The law states specific technology security requirements that all businesses in Massachusetts must follow.

 

Are you aware of all the rules? Is your business compliant? How do you know that all systems on your network are compliant?

 

We'll review the law in simple terms with a focus on the technology requirements, and provide the information you need to ensure compliance for your business.

 

If you're not 100% sure about the rules, this is a great opportunity to refresh your knowledge and make sure your business is protected.

 

When Thursday February 28th at 12:15pm

 

                                    Sign up today!

 

If you have any specific questions you'd like us to answer, let us know!

 

"Patch Tuesday" - February 2013

"Patch Tuesday" is the day each month that Microsoft releases their newest security updates, typically the second Tuesday of the month.  This month included twelve updates, including five "critical" updates and seven "important" updates. The updates impact Internet Explorer, Windows, Office... just about all users are affected:

 

 

Bulletin ID, Bulletin title and Executive Summary, Maximum Severity, Restart? Affected Software:

  • MS13-009 Cumulative Security Update for Internet Explorer (2792100) This security update resolves thirteen privately reported vulnerabilities in Internet Explorer.
    The most severe vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. CRITICAL, Requires restart, Microsoft Windows, Internet Explorer.
  • MS13-010 Vulnerability in Vector Markup Language Could Allow Remote Code Execution (2797052) This security update resolves a privately reported vulnerability in the Microsoft implementation of Vector Markup Language (VML). The vulnerability could allow remote code execution if a user viewed a specially crafted webpage using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. CRITICAL, May require restart, Microsoft Windows, Internet Explorer
  •  MS13-011 Vulnerability in Media Decompression Could Allow Remote Code Execution (2780091) This security update resolves one publicly disclosed vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a specially crafted media file (such as an .mpg file), opens a Microsoft Office document (such as a .ppt file) that contains a specially crafted embedded media file, or receives specially crafted streaming content. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. CRITICAL, May require restart, Microsoft Windows
  • MS13-012 Vulnerabilities in Microsoft Exchange Server Could Allow Remote Code Execution (2809279) This security update resolves publicly disclosed vulnerabilities in Microsoft Exchange Server. The most severe vulnerability is in Microsoft Exchange Server WebReady Document Viewing, and could allow remote code execution in the security context of the transcoding service on the Exchange server if a user previews a specially crafted file using Outlook Web App (OWA). The transcoding service in Exchange that is used for WebReady Document Viewing is running in the LocalService account. The LocalService account has minimum privileges on the local computer and presents anonymous credentials on the network. CRITICAL, May require restart, Microsoft Server Software
  • MS13-020 Vulnerability in OLE Automation Could Allow Remote Code Execution (2802968) This security update resolves a privately reported vulnerability in Microsoft Windows Object Linking and Embedding (OLE) Automation. The vulnerability could allow remote code execution if a user opens a specially crafted file. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. CRITICAL, Requires restart, Microsoft Windows
  • MS13-013 Vulnerabilities in FAST Search Server 2010 for SharePoint Parsing Could Allow Remote Code Execution (2784242)
    This security update resolves publicly disclosed vulnerabilities in Microsoft FAST Search Server 2010 for SharePoint. The vulnerabilities could allow remote code execution in the security context of a user account with a restricted token. FAST Search Server for SharePoint is only affected by this issue when Advanced Filter Pack is enabled. By default, Advanced Filter Pack is disabled. IMPORTANT, May require restart, Microsoft Office, Microsoft Server Software
  • MS13-014 Vulnerability in NFS Server Could Allow Denial of Service (2790978) This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow denial of service if an attacker attempts a file operation on a read only share. An attacker who exploited this vulnerability could cause the affected system to stop responding and restart. The vulnerability only affects Windows servers with the NFS role enabled. IMPORTANT, Requires restart, Microsoft Windows
  • MS13-015 Vulnerability in .NET Framework Could Allow Elevation of Privilege (2800277) This security update resolves one privately reported vulnerabilityin the .NET Framework. The vulnerability could allow elevation of privilege if a user views a specially crafted webpage using a web browser that can run XAML Browser Applications (XBAPs). The vulnerability could also be used by Windows .NET applications to bypass Code Access Security (CAS) restrictions. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. IMPORTANT, May require restart, Microsoft Windows, Microsoft .NET Framework
  • MS13-016 Vulnerabilities in Windows Kernel-Mode Driver Could Allow Elevation of Privilege (2778344)  This security update resolves 30 privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logs on to the system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit the vulnerabilities. IMPORTANT, Requires restart, Microsoft Windows.
  • MS13-017 Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (2799494) This security update resolves three privately reported vulnerabilities in all supported releases of Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logs on to the system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit the vulnerabilities. IMPORTANT, Requires restart, Microsoft Windows.
  • MS13-018 Vulnerability in TCP/IP Could Allow Denial of Service (2790655)  This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow denial of service if an unauthenticated attacker sends a specially crafted connection termination packet to the server. IMPORTANT Requires restart, Microsoft Windows.
  • MS13-019 Vulnerability in Windows Client/Server Run-time Subsystem (CSRSS) Could Allow Elevation of Privilege (2790113) This security update resolves a publicly disclosed vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker logs on to a system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. IMPORTANT, Requires restart, Microsoft Windows.

 For a full breakdown, check out the Microsoft Security Bulletin posted on line.  Note that in the days leading up to Patch Tuesday, there is always an advance notification, which gets replaced by the actual bulletin on the release date.

 

 A "critical" patch is defined by Microsoft as "a vulnerability whose exploitation could allow the propagation of an Internet worm without user action".  As a general rule, all critical patches should be installed as soon as possible. Also, if you have a managed service support plan with us, all patches are tested before installation, and we are tracking the updates for you.

 

Note that several of the security bulletins require reboots!  If you aren't regularly rebooting your systems, this is an important reminder.

 

Connect with us on line!
 
Follow us on Twitter Daily Small Business Tech News 
Like us on Facebook Please "Like" us for tech tips, news, and free training  
Visit our blog Subscribe to our blog for weekly tech tips
View our profile on LinkedIn Connect with us on LinkedIn

 

Does your business have a Facebook page or Twitter account? - Let us know so we can follow you too!

 

New! YouTube Training Videos - Check out our YouTube Channel - More training videos coming for 2013!  www.youtube.com/user/EkaruIT  If you need to do an "out of office" reply for an upcoming vacation, check out the video!


       Happy Valentines Day!

Introductory Technology Assessment Over 450 local small businesses have chosen Ekaru to manage their computers and networks. We offer a free, no-obligation initial consultation to get started. We'll visit your office, review your network, and make recommendations. Call us at 978-692-4200 or email us to schedule a no-obligation assessment. If you know someone who could benefit from this offer, simply forward this email to them. Thank You!

3
msbs
Microsoft Small Business Specialist
©2012 Ekaru, LLC. All Rights Reserved.