News

Light Microsoft Patch Expected Tuesday, Despite Threats

Microsoft plans to start the year with a light count of just two security bulletins in its January patch, according to an advance notice.

This month's security update, arriving Tuesday, will include only one "critical" item and one "important" item. Both security bulletins will address remote code execution risk considerations for Windows-based machines.

The critical item will affect every supported Windows operating system, while the important item will touch Windows Vista.

Security experts say it remains unclear what exactly will be addressed in this month's patch slate due to a handful of advisories and proof-of-concept threats under consideration. Moreover, the first security advisory of the year has already been published, which arrived last Tuesday. It describes a publicly disclosed vulnerability affecting the Windows graphics rendering engine for Windows XP, Vista and Windows Server 2003.

If this advance notice is any indication, new security issues with Internet Explorer won't be addressed this month.

"With only two bulletins this month, the big shock this month is that Microsoft is not addressing two security advisories that have already been weaponized," said Rapid7 Security Researcher Josh Abraham. "Microsoft has said they are going to 'continue to watch the threat landscape very closely.' However, I would bet that if the malicious attackers start using the exploits, then we will see an out-of-band patch."

The two security fixes to come may require restarts after installation.

For information about nonsecurity releases delivered through Windows Update and Microsoft Update, IT pros can take a look at this Microsoft Knowledge Base article.

About the Author

Jabulani Leffall is an award-winning journalist whose work has appeared in the Financial Times of London, Investor's Business Daily, The Economist and CFO Magazine, among others.

Featured

  • Get More Out of Your Outlook Inbox with TakeNote

    Brien comes across a handy, but imperfect, feature in Outlook that lets you annotate specific e-mails. Its provenance is something of a mystery, though.

  • Microsoft Resumes Rerelease of Windows 10 Version 1809

    Microsoft on Wednesday once more resumed its general rollout of the Windows 10 version 1809 upgrade, also known as the "October 2018 Update."

  • Microsoft Ups Its Windows 10 App Compatibility Assurances

    Microsoft gave assurances this week that organizations adopting Windows 10 likely won't face application compatibility issues.

  • SharePoint Online Users To Get 'Modern' UI Push in April

    Microsoft plans to alter some of the tenant-level blocking capabilities that may have been set up by organizations and deliver its so-called "modern" user interface (UI) to Lists and Libraries for SharePoint Online users, starting in April.

comments powered by Disqus
Most   Popular

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.