News

Duqu Flaw Looks To Go Unpatched in November's Light Patch Tuesday Release

Microsoft's Patch Tuesday is looking somewhat light for next week.

In an advance notice, Microsoft is projecting four Windows fixes to come. One is rated "critical" due to remote code execution implications. Two are deemed "important" because of remote code execution and elevation of privilege vulnerabilities. The last security bulletin in the bunch is expected to be a "moderate" fix to ward off denial of service attacks. This month's patch is expected to arrive on Nov. 8 at around 10:00 a.m. Pacific Time.

The critical item and one of the two important bulletins deal with fixing a remote code execution flaw in Windows Vista, Windows 7, Windows Server 2008 and Windows Server 2008 R2.

The second important bulletin concerns an undisclosed elevation of privilege flaw found in every supported version of Windows client OS and Windows Server.

Finally, Microsoft plans to release a "moderate" item this month, a denial of service fix,  for Windows 7 and Windows Server 2008 R2.

Restarts will be required for all but important bulletin No. 2, Microsoft expects.

Many would like to see a fix for a zero-day exploit in the Windows kernel that attackers can use to infect targeted systems with the Duqu Trojan worm. While Microsoft has acknowledged that it is working on a fix, the company provided no information in its advance notice that this fix will make it into November's patch.

More information can be found in Microsoft's Security Bulletin Advance Notification.

 

About the Author

Chris Paoli is the site producer for Redmondmag.com and MCPmag.com.

Featured

  • Windows Admin Center vs. Hyper-V Manager: What's Better for Managing VMs?

    Microsoft's preferred interface for Windows Server is Windows Admin Center, but can it really replace Hyper-V Manager for managing virtual machines? Brien compares the two management tools.

  • Microsoft Offers More Help on Windows Server 2008 Upgrades

    Microsoft this week published additional help resources for organizations stuck on Windows Server 2008, which fell out of support on Jan. 14.

  • Microsoft Ups Its Carbon Reduction Goals

    Microsoft on Thursday announced a corporatewide carbon reduction effort that aims to make the company "carbon negative" by 2030.

  • How To Dynamically Lock Down an Unattended Windows 10 PC

    One of the biggest security risks in any organization happens when a user walks away from their PC without logging out. Microsoft has the solution (and it's not a password-protected screensaver).

comments powered by Disqus

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.