Dear Visitor,

Our system has found that you are using an ad-blocking browser add-on.

We just wanted to let you know that our site content is, of course, available to you absolutely free of charge.

Our ads are the only way we have to be able to bring you the latest high-quality content, which is written by professional journalists, with the help of editors, graphic designers, and our site production and I.T. staff, as well as many other talented people who work around the clock for this site.

So, we ask you to add this site to your Ad Blocker’s "white list" or to simply disable your Ad Blocker while visiting this site.

Continue on this site freely
You are here: Home / Applications / MS Patch Tuesday To Be a Light One
Microsoft Shows Love to IT Admins with Light Patch Tuesday
Microsoft Shows Love to IT Admins with Light Patch Tuesday
By Jennifer LeClaire / CRM Daily Like this on Facebook Tweet this Link thison Linkedin Link this on Google Plus
Microsoft on Thursday offered some good news for IT admins via its advance notification service. Microsoft's February Patch Tuesday will include just nine bulletins, four of them "critical," to address 21 vulnerabilities.

Microsoft's February focus addresses vulnerabilities in Microsoft Windows, Office, Internet Explorer, and .NET/Silverlight. The five "important" rated security bulletins address vulnerabilities in Microsoft Visio Viewer 2010 in the Office productivity suite and Sharepoint, the advance notification advisory reported.

The Microsoft Security Response Center also took space in its advance notification blog post to note that information on Microsoft's Security Development Lifecycle system has been downloaded more than 850,000 times so far. And the Trustworthy Computing initiative is 10 years old.

Remote Code Executions

Marcus Carey, security researcher at Rapid7, said the four "critical" bulletins are rated so high because they allow remote code execution -- and three of them require a reboot for patching. Of the five "important" bulletins, two affect Microsoft Office.

The first bulletin is a core operating-system vulnerability that affects all modern deployed workstations and servers. The second bulletin is an Internet Explorer vulnerability allowing remote code execution.

"We're seeing a great many browser patches from Microsoft these days because researchers and attackers have realized that browser exploits have the most potential for harm and are currently the best attack surface," Carey said. "Browser-based attacks will certainly continue to be an attack vector from here on."

Bulletin No. 4 is the third critical over the last few months that patches .Net and Silverlight, Carey said, noting that media players and browser plug-ins are very popular attack vectors. Because browsers are effectively taking the role of operating systems for users, he explained, anything that can exploit the browser directly or indirectly will receive attention with exploit development and research.

Prioritizing Bulletins

"IT continues to benefit from Microsoft's security initiatives in 2012 with comparatively lower numbers year on year. Last February, we saw 12 security bulletins in all, three of which were critical and nine rated important," said Paul Henry, security and forensic analyst at Lumension.

From Henry's perspective, IT in February should prioritize the four critical bulletins first because each of them will likely require a restart. However, he noted, the light patch load from Microsoft does not mean IT can sit back and relax.

Henry pointed to a significant patch update from Oracle that came out recently, and as always, threats targeting Java must be addressed. He said Java is the largest threat vector today and is absolutely critical.

"All in all, it's a pretty sweet Valentine's. We've had two fairly light patching periods in a row -- with just seven from Microsoft last month," Henry said. "Clearly, the company's renewed focus is paying off. Now if folks would just follow through and patch."

Tell Us What You Think


Like Us on FacebookFollow Us on Twitter
© Copyright 2018 NewsFactor Network. All rights reserved. Member of Accuserve Ad Network.