Mobile App Security

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Monday, 11 February 2013

Get ready for major Microsoft security update

Posted on 08:41 by Unknown

Patch Tuesday will fix 57 bugs in IE, Windows, Office and Exchange Server

By Gregg Keizer | Computerworld US | Published 11:10, 11 February 13, computerworlduk
Microsoft will issue 12 security updates tomorrow, including two for Internet Explorer, that will patch a near-record 57 vulnerabilities in the browser,Windows, Office and the enterprise-critical Exchange Server email software.
"These are some serious numbers," said Andrew Storms, director of security operations at nCircle, referring to the 57 bugs Microsoft plans to quash tomorrow.
And they're nearly a record, coming close to the all-time Patch Tuesday tally of 64 flaws, all patched with fixes in April 2011.
  • Microsoft to issue emergency IE patch before next Patch Tuesday
  • Adobe Flash fix drags Google into Microsoft's Patch Tuesday
  • Microsoft targets Gmail privacy
Five of the updates will be pegged as "critical," Microsoft's highest threat rating, while the remainder will be labeled "important," the next step below critical.
Two of the five critical updates will address vulnerabilities in Windows XP Service Pack 3 (SP3) and Windows Vista. Among the important updates, five will affect Windows 7, four Windows 8, and three each for XP SP3 and Windows RT. The latter is the limited-functionality edition designed for tablets, and the one that powers Microsoft's own Surface RT tablet.
But what caught Storms' eye were the two separate updates for IE, both tagged as critical, that will patch IE6, IE7, IE8, IE9 and the latest browser, IE10.
"This is the first time I've seen them do this," said Storms of the one-two punch. "Unless there's been an 'out-of-band' update for IE, they've never released more than one update [for the browser] in a month."
Storms struggled to come up with ideas why Microsoft split what could have been one, albeit larger, update. "Why not just a cumulative update for IE?" he asked. "I certainly expect to see an interesting blog post next week with some long, convoluted explanation."
The most likely place where Microsoft would offer insight into why it crafted two IE updates is its Security Research & Defense blog, which regularly posts entries about complex or unusual updates from that month's Patch Tuesday.
The IE double-whammy could help enterprises manage patching next week. Or it could hurt them. "I can see it both ways," Storms said. "It may be more difficult because you have to test two updates. But it's also possible that they split them because one has more risk than the other." In the latter instance, enterprises will have more flexibility than usual, he said, and will be able to decide whether to apply only one, both or even neither.
"I can see that, but I still don't understand why they didn't put [all the patches] in one bulletin and wrap installation with some logic," said Storms. "[The only thing I can think of] is one bulletin is for the core of IE, and one is for something used by IE."
Another expert, Lumension security and forensic analyst Paul Henry, suggested that one of the IE updates might be related to recent vulnerabilities in Oracle's Java. Like other browsers, IE relies on an Oracle-provided plug-in to parse Java code.
"It's possible that this is related to the recent and ongoing Java issues," said Henry in an email. "Microsoft has a very close relationship with Oracle, so it wouldn't surprise me if these bulletins include Java patches."
Last week, Oracle accelerated the release of its regularly-scheduled security update -- initially slated to ship Feb. 19 -- citing "active exploitation 'in the wild' of one of the vulnerabilities affecting the Java Runtime Environment (JRE) in desktop browsers."
Oracle's early update came in the aftermath of several embarrassing "zero-day" vulnerabilities -- and the emergency patches necessary to quash those bugs -- as well as harsh criticism leveled by security professionals against Oracle for its handling of Java's problems.
Tomorrow's fifth critical update affects Exchange Server 2007 and Exchange Server 2010, the second- and third-most-recent versions of Microsoft's email server software.
While details were absent -- Microsoft's advanced notification is always bare bones -- Storms said the simple fact that the update was judged critical and for Exchange should be enough to raise the antenna of IT pros. "They always concern me because Exchange is the critical business application," said Storms.
A patch failure or compatibility problem in an Exchange update could conceivably knock out a firm's email, with all the resulting chaos that creates among workers, and the conflict between them and IT.
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in James Jones, Operating Systems, Web | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • LearningWorks: THE MISSING PIECE: Quantifying Non-Completion Pathways to Success
    ” . . . in the California Community College system . . . nearly one-third of students took an average of just two courses over about two yea...
  • Cisco Career Certifications Awarded American National Standards Institute Accreditation
    Achievement Demonstrates Compliance With Rigorous, Internationally Recognized Standards SAN JOSE, CA--(Marketwire - Jan 16, 2013) - Unders...
  • CyberWatch West Free Student 2 Student Webinar October 30th
    Online Workshop Oct 30 at 10:30 am PDT Man-in-the-Middle Attacks Using Mobile Devices Register @ cyberwatchwest.webex.com Student 2 Student ...
  • Spring 2013 NEW CCCApply Webinar Series
      Monday, 28 January 2013, TechEDge Written by Tim Calhoon Saturday, 26 January 2013 The New CCCApply online admissions application...
  • Community college grads out-earn bachelor's degree holders
    By Jon Marcus at The Hechinger Institute @CNNMoney February 26, 2013: 6:23 AM ET Nearly 30% of Americans with associate's degrees now ...
  • ACM CCECC Alice Summer Workshops Registration now open
    Registration has opened for the Alice Summer Workshops! A week has been set aside for a Community College focused workshop at Walt Disn...
  • CA Career Cafe: CALJOBS Job Search Service Now Available
    “ Somewhere someone is looking for exactly what you have to offer. ”                                                                    - ...
  • Code.org Launches To Help Make Computer Programming Accessible To Everyone
    Drew Olanoff ,  TechCrunch       Drew Olanoff has over 10 years of marketing, PR, customer service and support, relationship buildin...
  • EDGE goals addressed in 2013-14 California State Budget
    California's 2013-14 State Budget and an accompanying trailer bill, AB 86, address key EDGE goals of 1) beginning to restore dedicated f...
  • NCRIC Cyber Internship Program
    Northern California Regional Intelligence Center Cyber Internship Program Northern California Regional Intelligence Center (“NCRIC”) Mission...

Categories

  • Big Data
  • CATV
  • CENIC
  • Certifications
  • Cloud
  • Computational Thinking
  • Computer Engineering
  • Computer Science
  • CTE
  • Database
  • Digital Divide
  • Digital Literacy
  • Digital Media
  • Diversity
  • Educational Technology
  • elearning
  • Electronics
  • Entrepreneur
  • ethics
  • funding opportunity
  • Gaming
  • GIS
  • Grants
  • Hacking
  • Healthcare IT
  • ICT Applications
  • ICT Core Competencies
  • ICT Education
  • ICT Infrastructure
  • ICT Jobs
  • ICT pathways
  • ICT Regulation
  • ICT Research
  • Industry News
  • Innovation
  • Internships
  • James Jones
  • K-12
  • law
  • Linux
  • Mobility
  • MOOC
  • MPICT Announcements
  • Multimedia
  • Networking
  • networking security
  • Olivia Herriford
  • Open Source
  • Operating Systems
  • Pierre Thiry
  • Piracy
  • Public Policy
  • Security
  • Security; Identity Management
  • Smart Grid
  • Social Media
  • Soft Skills
  • Software Assurance
  • Software Engineering
  • Spanish
  • STEM Education
  • Storage
  • Teaching and Learning
  • Telecom
  • Tools
  • virtualization
  • Web
  • WIB
  • Wireless
  • women
  • Women in ICT
  • Workforce Development

Blog Archive

  • ▼  2013 (418)
    • ►  November (41)
    • ►  October (53)
    • ►  September (44)
    • ►  August (21)
    • ►  July (30)
    • ►  June (28)
    • ►  May (43)
    • ►  April (43)
    • ►  March (35)
    • ▼  February (43)
      • We Are Legion: The Story of the Hacktivists - Trailer
      • New CCC Information Security Officer
      • CENIC 2013: Building Blocks For Next Gen Networks
      • CCC TechEDge Security News 02.20.13
      • Sequestration to kill 1,000 NSF grants
      • Bandwidth-Throttling Copyright Enforcement System ...
      • Community college grads out-earn bachelor's degree...
      • Increasing Digital Literacy in Underserved Califor...
      • Dangerous Curves
      • Every student in every school should have the oppo...
      • Event – March 2: CalPERS to Host IT Career Fair
      • California Career Technical Education Model Curric...
      • House To Consider Bill That Would Establish Mobile...
      • Tech Predictions for 2013: It’s All About Mobile
      • CA Career Briefs: Stop Multitasking!
      • Center of Academic Excellence (CAE) in Information...
      • The Top Jobs for 2013
      • The 10 Skills That Will Get You Hired in 2013
      • CCC Chancellor's Office DWM Newsletter
      • NMC Horizon Report > 2012 Higher Ed Edition
      • Renewed Call for CCC Grant Readers
      • Phone rate hikes have landline customers ready to ...
      • FREE Security+, Information Storage Management and...
      • IT training gets an extreme makeover
      • How 802.11ac is set to transform wireless
      • Cassidy: MacArthur Foundation researchers find a n...
      • Get ready for major Microsoft security update
      • Government reorg plan may boost career track for s...
      • SF.CITI'S 2012 Year In Review| Transportation (MUN...
      • Robots Attract Students to ICT Programming (especi...
      • Cisco: Average North American Mobile Data Connecti...
      • CSSIA NSF ATE Center Featured on NSF's Science Nation
      • CCC Chancellor Brice Harris on Doing What Matters ...
      • Big MOOC Coursera Moves Closer to Academic Acceptance
      • Can the FCC Create Public "Super WiFi Networks"?
      • Tech accounts for up to 14% of January hiring
      • Get Experience at the Career Cafe
      • The Real Story Behind 'Super WiFi' And The Fight O...
      • How to encourage female students to consider STEM ...
      • The Myth of Population Density and the High Cost o...
      • Tech, telecom giants take sides as FCC proposes la...
      • Recruiting IT Workers? Here’s What You Need to Know…
      • University of California A-G Process Information
    • ►  January (37)
  • ►  2012 (82)
    • ►  December (25)
    • ►  November (40)
    • ►  October (17)
Powered by Blogger.

About Me

Unknown
View my complete profile