News

Duqu Flaw Looks To Go Unpatched in November's Light Patch Tuesday Release

Microsoft's Patch Tuesday is looking somewhat light for next week.

In an advance notice, Microsoft is projecting four Windows fixes to come. One is rated "critical" due to remote code execution implications. Two are deemed "important" because of remote code execution and elevation of privilege vulnerabilities. The last security bulletin in the bunch is expected to be a "moderate" fix to ward off denial of service attacks. This month's patch is expected to arrive on Nov. 8 at around 10:00 a.m. Pacific Time.

The critical item and one of the two important bulletins deal with fixing a remote code execution flaw in Windows Vista, Windows 7, Windows Server 2008 and Windows Server 2008 R2.

The second important bulletin concerns an undisclosed elevation of privilege flaw found in every supported version of Windows client OS and Windows Server.

Finally, Microsoft plans to release a "moderate" item this month, a denial of service fix,  for Windows 7 and Windows Server 2008 R2.

Restarts will be required for all but important bulletin No. 2, Microsoft expects.

Many would like to see a fix for a zero-day exploit in the Windows kernel that attackers can use to infect targeted systems with the Duqu Trojan worm. While Microsoft has acknowledged that it is working on a fix, the company provided no information in its advance notice that this fix will make it into November's patch.

More information can be found in Microsoft's Security Bulletin Advance Notification.

 

About the Author

Chris Paoli is the site producer for Redmondmag.com and MCPmag.com.

Featured

  • Vendors Issue Patches for Linux Container Runtime Flaw Enabling Host Attacks

    This week, the National Institute of Standards and Technology (NIST) described a high-risk security vulnerability (CVE-2019-5736) for organizations using containers that could lead to compromised host systems.

  • Windows 10 Version 1809 Users May Get Visual Studio Crashes

    Microsoft on Friday issued an advisory for Windows 10 version 1809 users about possible Visual Studio crashes.

  • Standardizing the Look of Outlook's Outbound Messages

    Microsoft typically gives users a blank canvas to compose new e-mails in Outlook. In some corporate environments, however, a blank canvas isn't a good thing.

  • Windows 10 'Semiannual Channel Targeted' Goes Away This Spring

    Microsoft plans to slightly alter its Windows servicing lingo and management behavior with its next Windows 10 operating system feature update release, coming this spring.

comments powered by Disqus

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.