Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Microsoft re-patches last month's critical IE update

Third correction traced to October's massive Patch Tuesday

November 3, 2009 11:47 AM ET

Computerworld - Microsoft yesterday re-patched Internet Explorer, the third time it's been forced to repair one of the updates from its largest-ever bug fix, which was delivered on Oct. 13.

Monday's fix targeted MS09-054, the update that patched four vulnerabilities, all "critical," in Internet Explorer (IE). According to Christopher Budd, a spokesman for the Microsoft Security Response Center (MSRC), the follow-up hotfix patches Web page display problems introduced by the update. Budd downplayed the severity of the problems, saying that the number of users affected was "limited."

A document on Microsoft's support site outlined the two issues, one that scrambles Web page elements, while the other spawns a "Type Mismatch" script error on sites that use VBScript or a mix of VBScript and JavaScript.

The new problems can crop up in any still-supported edition of IE, including IE 5.01, IE6, IE7 and the newest version, IE8, on all Windows operating systems, including Windows 7.

The troubles are serious enough to prompt Microsoft to push the re-patch to all users. "We plan to release this update through the same broad release channels as the original security update, MS09-054," Budd said in an entry to the MSRC blog yesterday. "Customers will see [the re-patch] offered by default through Windows Update, Microsoft Update and Automatic Updates."

Computerworld confirmed that Windows XP, Vista and Windows 7 systems that had been fully patched last month were offered Monday's update through Windows Update.

Monday's re-patch was the third correction related to Oct. 13's massive security update, which set records for both the number of separate bulletins (13) and the number of vulnerabilities quashed (34).

On Oct. 14, Microsoft offered up a workaround for a problem with MS09-056, then corrected several errors in MS09-062 last Thursday.

The company also revised an August update, MS09-043, last week to correct a patch-detection error that may have left some corporate users who receive updates via Windows Server Update Services (WSUS) unpatched.

It's not unusual for Microsoft to re-release security updates. In June 2008, for example, the company admitted a patch intended to fix a problem in Windows XP's implementation of Bluetooth didn't work. Microsoft blamed human error for the snafu.

The update for MS09-054 can be downloaded from Microsoft's site, or retrieved using Windows Update or WSUS.

Microsoft update notification
Microsoft pushed the re-patch of last month's IE security update to users via Windows Update.


Jump to comments

IE update

Additional Resources

Xerox
By using solid ink technology only from Xerox, you could save up to 65% by printing color for the cost of black and white. Enter for a chance to WIN a PhaserTM 8860 network color printer!
Microsoft
Save time and mitigate security risk. Deploy it now.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

What People Are Saying

White Papers & Webcasts

Share our Strength
Download Now  

Managing Secure File Transfer to Save Time, Money and IT Resources
Learn how companies are using innovative technology to overcome these challenges and improve user productivity by offloading e-mail attachments and replacing FTP with...

Security Convergence Equals Network Security Cost Savings
Listen to IBM Internet Security Systems' take on network security convergence.

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...