ITPRO

Printed from www.itpro.co.uk

Register to receive our regular email newsletter at http://www.itpro.co.uk/reg/register.

The newsletter contains links to our latest IT news, product reviews, features and how-to guides, plus special offers and competitions.

Skip to navigation

    Just one patch from Microsoft next week

The software giant has said it is planning to issue only one patch next week.

By Miya Knights, 9 Jan 2009 at 11:03

Microsoft is set to release just one update as part of its monthly round of security patches, due next Tuesday.

Last month, the software maker issued its largest ever ‘Patch Tuesday’ bulletin, containing eight fixes which addressed 28 vulnerabilities.

While details were scarce on exactly which flaws next week's patch would address, the security bulletin preview did say that the update had been given Microsoft's highest security rating of ‘critical’, and that it would address both server and desktop versions of its Windows operating system (OS).

The flaws could allow attackers to install unauthorised software on a victim’s computer, it added.

Despite the scant detail, there are a number of bugs affecting the Windows OS that Microsoft could be planning to fix.

In the last month alone, Microsoft warned about flaws uncovered in its TextConverter, WordPad and SQL Server database software.

Security vendor SecurityFocus said at the end of December that it had uncovered a remote code execution flaw in versions 9, 10 and 11 of Microsoft’s Windows Media Player running on Windows Vista or XP, which it outlined in a blog posting on its Bugtraq website.

Microsoft was quick to respond with a posting of its own on the Microsoft Security Centre blog, admitting that the code posted in the Bugtraq blog could crash the player, but dismissing SecurityFocus’s claim that it could compromise the security of the rest of a Windows system.

One recent flaw Microsoft won’t have to address was discovered in Internet Explorer 7 in December. The software maker deemed the vulnerability, which allowed hackers to install password-stealing software on affected PCs, to be so serious it rushed out a patch within eight days, outside of the regular round of monthly patching.

Email to a friend

Print this page

< Previous   Security : News Next >

Be the first to comment on this article

You need to Login or Register to comment.

 Sponsored Links

advertisement
advertisement

    Register for IT PRO

You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.

Sponsored Links
Advertisement