Microsoft slates 25-patch Windows update for next week
Double-digit Patch Tuesday to target flaws in Windows, Office and Exchange
Computerworld - Microsoft today said it would deliver 11 security updates next week to patch 25 vulnerabilities in Windows, Office and Exchange.
"Big day next Tuesday," said Andrew Storms, director of security operations at nCircle Network Security, of the patch news.
In its monthly advance notification, Microsoft spelled out next week's double-digit Patch Tuesday, which is entirely in line with company's pattern of alternating large- and small-sized updates, said Storms. "This fits with what we expected," he said, "a double-digit bulletin [Patch Tuesday] and double-digit CVEs."
The latter, for Common Vulnerabilities and Exposures, is the identifying number each individual vulnerability receives when it's logged into the public CVE database. "We get this up-and-down from Microsoft now."
Last month, Microsoft issued only two updates that patched six vulnerabilities; February's security fixes came in 13 bulletins that fixed 26 flaws.
"The good news is that Microsoft is fixing two outstanding bugs," Storms continued.
Storms was referring to news from Jerry Bryant, a group manager with the Microsoft Security Response Center (MSRC), who said that among the 11 updates would be two that patch previously-acknowledged vulnerabilities. Microsoft disclosed the bugs in November 2009 and March 2010.
The March security advisory warned Windows XP users not to press the F1 key when prompted by a Web site, Microsoft's response to a report by Polish security researcher Maurycy Prodeus of a vulnerability in VBScript that attackers could exploit to hijack PCs running Internet Explorer (IE).
The November 2009 warning was prompted by reports of a bug in SMB (Server Message Block), a Microsoft-made network file- and print-sharing protocol, within Windows 7 and Windows Server 2008 R2, Microsoft's newest operating systems. At the time, the flaw was the first Microsoft-confirmed zero-day vulnerability for Windows 7.
- Radicati: Cloud Business Email - Market Quadrant 2013 Google was named the top cloud business email provider in a recent report by research firm Radicati. Out of 14 key players, Google...
- Tablets in the Enterprise: A Checklist for Successful Deployment How can you enterprise manage and secure tablets in order to protect corporate data while providing access to the information and applications employees...
- Enterprise Mobility: A Checklist for Secure Containerization The advantages and disadvantages of the multiple approaches to containerization. Learn More>>
- Enterprise File Sync & Share Checklist File sync and share has changed the way people work and collaborate in today's tech-savvy world. Gone are the email roadblocks, clunky FTP...
- Live Webcast LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy... All Security White Papers | Webcasts