Microsoft slates colossal Windows patch next week
Ties record with 13 security updates, plans to fix 26 bugs in Windows, Office
Computerworld - Microsoft today said it will deliver a record-tying 13 security updates on Tuesday to patch more than two dozen vulnerabilities in Windows and Office.
The company will ship a total of 13 updates next week, five of them pegged "critical," the highest threat ranking in its four-step scoring system. The 13 updates will tie the record from October 2009, when Microsoft issued the same number of bulletins, but fixed a total of 34 vulnerabilities. According to Jerry Bryant, a senior manager with the Microsoft Security Response Center (MSRC), next week's updates will patch 26 flaws.
"A lot? That's an understatement," said Andrew Storms, director of security operations at nCircle Network Security. "But we could have had 14," he added, referring to the emergency Internet Explorer (IE) update Microsoft released two weeks ago. That "out-of-band" update was originally slated to be included in the collection set to ship this month.
Of the eight updates not marked critical, seven were ranked "important," the next-lower rating, while one was pegged "moderate." Eleven of the 13 will affect one or more editions of Windows; the remaining pair will affect Office XP and Office 2003 on Windows, and Office 2004 for Mac.
"What's kind of interesting this month is that there are fewer applications updates," said Storms, talking about the 11-to-2 ratio of Windows-to-Office security bulletins. The trend, Storms noted, has been the opposite: Microsoft applications, primarily Office and IE, have been extensively exploited by hackers, who have shied away from Windows itself because attacking applications has been easier.
That's not to say there isn't evidence of long-standing trends in the massive matrix that Microsoft spelled out in today's advance notification. One trend: Newer software is generally more secure than older software.
"We know that the newer operating systems are more secure," said Storms. "They use newer code, and were created with SDL [Security Development Lifecycle]," he added. SDL is Microsoft's term for a programming philosophy that bakes security awareness into all aspects of development. As proof, Storms pointed to Windows Server 2008 R2, the newest version of Microsoft's server software. "It has the least number of bulletins," he said.
Server 2008 R2 will be affected by 5 of the 11 Windows updates. Windows 7, the newest client operating system, will be impacted by the same percentage, 45%, of the total. The eight-year-old Windows XP, meanwhile, will require 8 of the 11, or 73% of Windows updates, while the even older Windows 2000 will be affected by 9 of the 11, or 82% of the total.
"Every month, there's a new reason to get off the older operating systems, to get off the older applications," said Storms.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Driving Secure Enterprise File Sharing and Syncing in the Enterprise
- GroupLogic's new activEcho is the industry's only secure Enterprise File Sharing and Synching solution that balances the need for simplicity for the end...
- The Enterprise File Sharing Option
- Enterprises and IT departments need to address several critical security issues when considering file sharing and syncing products. Many of today's solutions do...
- Security Strategies to Virtualizing Internet-Facing Applications
- The IT organization at Intel has set a goal to transition their enterprise to a private cloud for their Office and Enterprise applications....
- Cloud Security Planning Guide
- Cloud security considerations span protecting hardware and platform technologies in the data center to enabling regulatory compliance and defending cloud access through different...
- Cloud Security Vendor Round Table
- This vendor round table guide will help you to evaluate different cloud technology vendors and service providers based on a series of questions... All Security White Papers
- Live Webcast
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute - Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
- Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - Security Certifications 101 - BlackBerry and all those acronyms what do they mean and why they matter?
- FIPS, Common Criteria, CAPS, AISEP, NFC, NIST, Fraunhofer SIT, CESG, DSD - these are just some of the government and industry certifications which...
- BlackBerry PlayBook OS 2.0 Security Overview
- The presentation provides an overview of BlackBerry PlayBook OS 2.0 security capabilities and features, including: BlackBerry® Balance™ technology, BlackBerry® Bridge, data-at-rest protection, and...
- BlackBerry NFC Security Overview
- The presentation on NFC security will provide an overview of the security protections built into the BlackBerry platform to protect users, application developers...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts