Microsoft to patch IE10 Pwn2Own bugs next week, says security expert
Slates nine security updates for IE, Windows, SharePoint and Defender on Windows 8, RT
Computerworld - Microsoft today said it will ship nine security updates next week, two rated "critical," to patch Internet Explorer (IE), Windows, SharePoint Server, Office Web Apps and the company's anti-malware software in Windows 8 and RT.
One security expert put his money on the IE update as the most important of the pending, in part because he expects Microsoft to fix the flaws revealed a month ago at the Pwn2Own hacking contest.
"Microsoft will patch the vulnerability from Pwn2Own [in IE10]," said Andrew Storms, director of security operations at Tripwire. "It has to. If it doesn't, it would be no better off than it was before, when it patched IE every other month."
Storms was referring to the two vulnerabilities that a team from the French firm Vupen exploited at Pwn2Own. Vupen won $100,000 for demonstrating the exploit of IE10 on Windows 8 Pro running on a Surface Pro tablet.
The bugs, Vupen said four weeks ago, existed in both the desktop version of IE10 on Windows 8 as well as in the "Modern"-style browser that runs on the tile-based user-interface (UI) once dubbed "Metro."
Google and Mozilla patched the vulnerabilities disclosed in their Chrome and Firefox browsers within hours of the contest, but Microsoft has yet to issue a post-Pwn2Own fix for IE.
April's Patch Tuesday will be on par with Microsoft's releases in 2013, which have averaged nine each month thus far in the year. Last year, the monthly average was 6.9 updates, Storms said.
Two of the updates will be ranked critical, Microsoft's top threat rating, while the remaining seven will be tagged as "important," the next ranking below critical.
Like last month, the most notable was the one that will patch all supported versions of IE, including the 12-year-old IE6, IE7, IE8, IE9 and also the newest, IE10. "Bulletin 1," as the update was identified today in Microsoft's monthly advance warning of the upcoming updates, affects IE10 on Windows 7, Windows 8 and Windows RT.
It will be the first critical update to IE10 on Windows 7 since the new browser was launched on that operating system in late February.
Next week's IE patches will be the fourth month in a row that Microsoft has quashed bugs in its browser, and the ninth month out of the last 10 with an IE update. Last July, Microsoft announced it had beefed up the IE security and patching teams, and would be able to issue monthly updates rather than every other month, as had been its practice for years.
Also on next week's agenda will be a critical update to all client editions of Windows except for Windows 8 and Windows RT; those will be unaffected, Microsoft said.
- Radicati: Cloud Business Email - Market Quadrant 2013 Google was named the top cloud business email provider in a recent report by research firm Radicati. Out of 14 key players, Google...
- Tablets in the Enterprise: A Checklist for Successful Deployment How can you enterprise manage and secure tablets in order to protect corporate data while providing access to the information and applications employees...
- Enterprise Mobility: A Checklist for Secure Containerization The advantages and disadvantages of the multiple approaches to containerization. Learn More>>
- Enterprise File Sync & Share Checklist File sync and share has changed the way people work and collaborate in today's tech-savvy world. Gone are the email roadblocks, clunky FTP...
- Live Webcast LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy... All Security White Papers | Webcasts