Thursday, 23 February 2012

Guest Blog from Greg Lambert: The Internationalization of Quest ChangeBASE

Here's a sneaky peak at what's happening on Greg Lambert's Application Compatibility Blog.

Check out more from Greg -

The Internationalization of Quest ChangeBASE

  • Spanish
  • French
  • German
  • Italian
  • Russian
  • Portuguese
You can now  find the ChangeBASE application compatibility product descriptions in your language of choice at the following locations;

This should really help out those working with ChangeBASE in Latin America and in Europe.  And when I am in Berlin next, I think it will be really helpful for me to be able to say ;
"Schnelle, automatische Anwendungsbereitschaft für Microsoft Windows und Office, virtualisierte Desktop- und applikationsbezogene Umgebungen und neue Browser-Versionen" 
And since you may not speak any of the above languages (I wish I could speak Italian), we have a new video available from Quest. This is similar to the previous animated series and does a great job explaining vWorkspace.

You can view the Quest vWorkspace video  here:

Wednesday, 15 February 2012

Microsoft Patch Tuesday - February 14, 2012

Application Compatibility Update with Quest ChangeBASE

Executive Summary
With this February Microsoft Patch Tuesday update, we see a set of 9 updates; 4 with the rating of Critical and 5 with the rating of Important. This is a moderately large update from Microsoft, with one notably large payload (MS12-011); however the potential compatibility impact for these updates is likely to be low.

As part of the Patch Tuesday Security Update analysis performed by the ChangeBASE team, we have seen a small number of potential compatibility issues caused by updates MS12-011, MS12-013 and MS12-015. All identified issues are designated at Amber issues by Quest ChangeBASE, as they would be relatively straight forward to fix with no serious compatibility impact.

Given the nature of the changes and updates included in each of these patches, most systems will require a reboot to successfully implement any and all of the patches and updates released in this February Patch Tuesday release cycle.

Sample Results

Here is a sample of the results for an application tested for compatibility with these updates:

MS12-01 Vulnerability in C Run-Time Library Could Allow Remote Code Execution

And here is a sample Summary report for a sample database where the Quest ChangeBASE Patch Impact team has run the latest Microsoft Updates against a small application portfolio:

Quest ChangeBASE RAG Report Summary

Security Update Detailed Summary

Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (2660465)
This security update resolves a privately reported vulnerability and a publicly disclosed vulnerability in Microsoft Windows. The more severe of these vulnerabilities could allow remote code execution if a user visits a website containing specially crafted content or if a specially crafted application is run locally. An attacker would have no way to force users to visit a malicious website. Instead, an attacker would have to convince users to visit the website, typically by getting them to click a link in an email message or Instant Messenger message that takes them to the attacker's website.
Win32k.sys, Updspapi.dll, W32ksign.dll
Critical - Remote Code Execution

Vulnerabilities in Ancillary Function Driver Could Allow Elevation of Privilege (2645640)
This security update resolves two privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logs on to a user's system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit the vulnerabilities.
Afd.sys, Updspapi.dll
Important - Elevation of Privilege

Cumulative Security Update for Internet Explorer (2647516)
This security update resolves four privately reported vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted web page using Internet Explorer. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
No specific files
Critical - Remote Code Execution

Vulnerabilities in Microsoft SharePoint Could Allow Elevation of Privilege (2663841)
This security update resolves three privately reported vulnerabilities in Microsoft SharePoint and Microsoft SharePoint Foundation. These vulnerabilities could allow elevation of privilege or information disclosure if a user clicked a specially crafted URL.
Important - Elevation of Privilege

Vulnerability in Color Control Panel Could Allow Remote Code Execution (2643719)
This security update resolves one publicly disclosed vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a legitimate file (such as an .icm or .icc file) that is located in the same directory as a specially crafted dynamic link library (DLL) file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Colorcpl.exe, Colorui.dll, Icmui.dll
Important - Remote Code Execution

Vulnerability in C Run-Time Library Could Allow Remote Code Execution (2654428)
This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a specially crafted media file that is hosted on a website or sent as an email attachment. An attacker who successfully exploited the vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Critical - Remote Code Execution

Vulnerability in Indeo Codec Could Allow Remote Code Execution (2661637)
This security update resolves one publicly disclosed vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a legitimate file (such as an .avi file) that is located in the same directory as a specially crafted dynamic link library (DLL) file. An attacker who successfully exploited this vulnerability could run arbitrary code as the logged-on user. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. If a user is logged on with administrative user rights, an attacker could take complete control of the affected system. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Iacenc.dll, Updspapi.dll
Important - Remote Code Execution

Vulnerabilities in Microsoft Visio Viewer 2010 Could Allow Remote Code Execution (2663510)
This security update resolves five privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially crafted Visio file. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Saext.dll, Seqchk10.dll, Vpreview.exe, Vviewdwg.dll, Vviewer.dll
Important - Remote Code Execution

Vulnerabilities in .NET Framework and Microsoft Silverlight Could Allow Remote Code Execution (2651026)
This security update resolves one publicly disclosed vulnerability and one privately reported vulnerability in Microsoft .NET Framework and Microsoft Silverlight. The vulnerabilities could allow remote code execution on a client system if a user views a specially crafted web page using a web browser that can run XAML Browser Applications (XBAPs) or Silverlight applications. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
No specific files
Critical - Remote Code Execution

*All results are based on a Quest ChangeBASE Application Compatibility Lab’s test portfolio of over 1,000 applications.

For more info about Quest ChangeBASE, please visit

Thursday, 9 February 2012

Quest vWorkspace and ChangeBASE team up for the ultimate in browser compatibility solutions

IE6 is firmly becoming a bad word in the world of Microsoft, as this legacy browser version is now the biggest hurdle preventing organisations across the globe from fully embracing Windows 7. With Quest's acquisition of ChangeBASE, two technologies have now come together to enable organisations to finally get off IE6 for good.

Quest ChangeBASE Browser Compatibility helps you achieve application readiness by assessing your web sites and web-based applications for compatibility with Internet Explorer 8 or 9. This unique, automated solution provides a quick, easy and cost-saving approach to web applications and web site testing, whether they’re on the internet, intranet or extranet. With the extensive range of automated compatibility checks included, you can ensure browser upgrades or updates don’t cause incident or an unnecessary burden on IT resources. The detailed reports help you to prioritize remediation and ensure that the issues with the greatest impact will get resolved first. And don't just take Quest's word for it - TechWorld named ChangeBASE's browser compatibility tool as Enterprise Product of the Year 2011.

And for those IE6 issues that can't be fixed, Quest vWorkspace provides an elegant solution with its virtualisation capabilities. vWorkspace lets you deploy a blended virtualisation model – pairing the appropriate technologies to users based on their unique needs while keeping the average cost per virtual desktop to a minimum. In developing the IE 6 Compatibility Edition, Quest has taken the current release of vWorkspace, explicitly locked it down so that it will only run Internet Explorer and extended it by offering the capability to redirect named URLs to IE 6 while others are processed by whatever browser is locally set as the default. On his Virtualization Practice blog, Simon Bramfitt says that vWorkspace "represents a pragmatic solution to an awkward dependency on legacy development standards".

We're really excited about the opportunity presented by pairing these two capabilitites for taking on the IE6 challenge, so if this sounds like a solution for your organisation, get in touch.

And if you're in the UK, Quest are giving you the opportunity to learn more about these technologies in a 1 day event at Old Trafford Stadium in Manchester - and you'll get a guided tour of Manchester United's ground too!

Wednesday, 1 February 2012

Quest Software launches Quest ChangeBASE products

It gives me enormous pleasure to announce the general availability (GA) of the three Quest ChangeBASE products.

Since Quest Software acquired the people and products of ChangeBASE last October, we’ve been working hard to integrate the two companies as well as rebrand the products and determine new product roadmaps.

The results are now here, and are available from both the main Quest Software pages and from the site of ScriptLogic, a wholly-owned subsidiary of Quest Software.

Quest ChangeBASE is all about application readiness. This means: making your applications ready for new platforms, new versions of platforms and new patches. Change happens all the time – it’s not just e.g. Windows 7, it’s also application releases and patches, application and desktop virtualization (especially terminal servers) and let’s not forget Patch Tuesdays, driver updates… it goes on and on.

So, maintaining a healthy application estate is all about approaching change with two things in mind:

1.     Change is never over. Think of a continuous process, not a single migration.
2.     Automation. Automate as much as you can – from application discovery (what’s out there, what’s being used) through application assessment (what will work on the new platform/with the new version), automated fixing and (if you’re going for application virtualization), automated virtualization. Outsourcing to an off-shore lab where all testing is manual may get you to Windows 7 (but it’ll be expensive – and slow – and may miss key issues), but it won’t help you deal with the constant change of patches, updates and versions.

Today, we launch three new products: ChangeBASE Standard, ChangeBASE Professional and ChangeBASE Browser Compatibility. All three are one-stop shop solutions for specific Application Readiness use-cases. All three provide quality, detailed, automated application compatibility assessment for particular target platforms. The details are to be found on the websites, but the broad-brush picture is: if you want to assess and fix compatibility of your applications with Windows 7 or Office, look at ChangeBASE Standard. If you also want to assess for suitability with application virtualization or terminal servers, look at ChangeBASE Professional. ChangeBASE Professional can also automate the virtualization of your applications. If you want to understand if your website and web apps will work with the newest versions of Internet Explorer, look at ChangeBASE Browser Compatibility.

All three products feature short-time-to-value, download-and-go and extensive automation. All three will radically accelerate your platform migrations as well as the ongoing management of your application estate. Exactly the same trial version of Quest ChangeBASE is available from both the Quest Software site (here) and from the ScriptLogic site (here).

Finally, for those who are already ChangeBASE customers: thank you! No functionality has been lost in this rebranding and repackaging. Get in touch and we can walk you through how the new products map to what you have.
Before we acquired them, ChangeBASE had already amassed a great set of customers all around the world. We look forward to welcoming you to Quest ChangeBASE.


Hugh McEvoy
Manager, Product Management
Quest Software