Microsoft plans big May patch slate for next week
Schedules seven updates to patch 23 bugs in Windows, Office
Computerworld - Microsoft today said it would ship seven security updates next week, three critical, to patch 23 bugs in Windows, Office and its Silverlight and .Net development platforms.
The number of patches -- nearly two dozen -- is higher than usual for an odd-numbered month; for some time, Microsoft has used an even-odd schedule, patching more vulnerabilities in the even months, when it also regularly updates Internet Explorer.
"May has been a light month, historically, very light," said Andrew Storms, director of security operations at nCircle Security, who tracks the number of patches and updates Microsoft issues each month.
In May 2011, Microsoft shipped two update that patched three vulnerabilities. The year before, it delivered two updates that patched two bugs.
"So, this is a big number," said Storms.
The pace so far this year -- Microsoft's collections during the first five months have included seven, nine, six, six and seven updates -- puts to rest the idea that Microsoft still hews to a wave-and-trough practice.
"Certainly for bulletin count, it looks like a pretty flat line to me," said Storms, using the term "bulletin" -- Microsoft's label -- to describe security updates. "This year, it looks like the up and down pattern has ended."
Wolfgang Kandek, CTO of Qualys, agreed with Storms.
"In prior years we have seen much stronger differences [in the number of updates each month], ranging from 2 to 17," Kandek said in an email. "We are not sure this [flattening] is intended, but it makes the workload much more predictable and is preferable to the more bursty release mode."
Of the seven updates, Microsoft tagged three as "critical," the highest threat ranking in its four-step system, and the other four as "important," the next-most serious score.
Four updates will address vulnerabilities in Windows; four will impact Office, Microsoft's popular application suite; and one will affect the Silverlight development framework. That count exceeds seven because one of updates tackles bugs in all three of those lines.
The large number of Office updates caught Storms' eye: Three of the pending bulletins are Office-only, while one is shared with Windows and Silverlight. The trio of Office-only updates will patch flaws in Word, Excel and Visio. The latter is a little-used commercial diagramming program that's considered part of the Office family.
"There's a heavy lean toward Office here," Storms noted.
Storms pointed his finger at what Microsoft labeled Bulletin 2 as the most likely to rise to the top of the to-do list next week. His reasons: It was pegged critical, impacts virtually every edition of Windows, applies to all currently-supported versions of Office on Windows and also patches one or more bugs in Silverlight.
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Case Study: Hospital Turns to Email Archiving Solution to Ensure Regulatory Compliances Read this case study to learn how a cloud-based email archiving solution enabled the hospital to meet government mandates and helps avoid thousands...
- Case Study: In-the-Cloud Email Service Replaces Three Point Products Read this case study for more information on a comprehensive in-the-cloud email service to help replace three point products.
- What does it take to deliver Security, Privacy and Trust at Mimecast? This whitepaper explains the process and controls that Mimecast put in place to deliver a secure, private and trusted SaaS platform for your...
- Your Data under Siege: Defeating the Enemy of Complexity Even if you have adequate antivirus protection, are there still holes in your IT security armor? Is lack of bandwidth to manage the...
- Live Webcast
Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider - Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider
- Live Webcast
MFT and FileXpress - An Overview - Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity.
- Live Webcast
Bridging HTTP and FTP with FileXpress Internet Server - What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Security White Papers | Webcasts