Microsoft released four patches - all rated important - as part of its regular Patch Tuesday update cycle, one of which left ZoneAlarm users locked out the internet. Tomorrow when my left ear recovers, I\’ll call the MS 866 number (866-PCSAFETY) and see if I can patch the MS problem w/o hosing my internet connection again. 3 hours of ATT tech (hahahaha) support later, after telling them I suspected the update, and that I ran ZA, I finally reached a person who told me about this conflict. The experiences of Reg reader Steve seem typical.
This flaw - along with cross-site scripting vulnerabilities in Outlook for Web Access that affect MS Exchange and information disclosure bugs in SQL Server - are all rated \”important\” by Redmond but \”critical\” by security watchers at the SANS Institute\’s Internet Storm centre. Symptoms: all network software reports you are connected but you\’re NOT. A vnunet. The most significant of the quartet fixes a flaw in Windows\’ implementations of the Domain Name System protocol.
Not sure who is to blame on this one but it has been a pain. ZoneLabs has issued a preliminary advisory detailing workarounds for ZoneAlarm users who have been locked out of their internet connections by Microsoft\’s latest round of bug fixes. \”The XP update dated 7/8/08 does not play well with systems running Zone Alarm. The Explorer vuln potentially creates a means for hackers to inject malware onto vulnerable systems running Windows Vista.
\”I wish I could give you the name of the file, but I uninstalled it, during the process (finally fixed it myself, btw) and told it not to tell me about it again. Microsoft\’s three other patches cover vulnerabilities in Exchange server and SQL Server and, on the desktop, bugs in Windows Explorer. Zone Alarm users locked out of the Internet by Microsoft weekly update. A final resort, which ZoneLabs does not recommend, is reducing the security level of ZoneAlarm to medium for the internet zone.
Successfully exploiting the flaw could allow hackers to spoof DNS replies, creating a means to redirect network traffic or to mount man-in-the-middle attacks. \”I have uninstalled Zone Alarm and everything now works fine. Microsoft locks Zone Alarm users out of the Internet. The first recommended action is to uninstall the hotfix via the Windows \’Add and Remove Programs\’ menu.
com Forum visitor confirmed that removing the Microsoft update solves the problem. ZoneLabs confirmed that the Microsoft patch cripples platforms including ZoneAlarm Free, ZoneAlarm Pro, ZoneAlarm AntiVirus, ZoneAlarm Anti-Spyware and ZoneAlarm Security Suite. POP3 does not connect; web pages do not display. The firm issued three possible solutions for the unknown percentage of the hundreds of thousands of users of its popular ZoneAlarm firewall who have fallen foul of the Patch Tuesday \’fixes\’.
\”Zone Alarm locked out by Microsoft update. \”ZoneAlarm has published a list of recommended workarounds to dealing for the glitch here. Multiple vendors are subject to the DNS-spoofing vulnerability, which stems from a fundamental weakness involving a lack of entropy in DNS queries rather than a specific security bug. mspx).
\”I woke up this morning to no internet at all and on calling my ISP\’s tech support I was told there was an issue with the latest patches and Zone Alarm,\” he reports. Zone Alarm issues work around for Microsoft lock-out.