Microsoft Readying 9 Security Bulletins for February Update
While this month's Patch Tuesday will land on Valentine's Day, Microsoft will be delivering nine not-so-sweet bulletin items -- with four of them being classified as "critical" and five "important."
All four of the critical bulletins will take care of remote code execution flaws for multiple versions of Windows, Microsoft .NET Framework and Microsoft Silverlight. As for the five less-critical items, they will attack both elevation of privilege and remote code execution holes in Windows, Office and Microsoft Server Software.
While the somewhat large number of bulletins this month is not unusual for February's Security Update, what is out of the ordinary is the fact that Microsoft's OS is getting so much attention. "Their advance notification indicated they plan to release nine bulletins, and 21 CVEs next Tuesday," wrote Andrew Storms, director of security operations for nCircle. "This is very consistent with last year's 'valentine delivery' that included 12 bulletins and 22 CVEs. It's surprising that this month's patch affects almost every Windows operating system -- each OS is affected by five of the eight applicable bulletins."
Storms continues by discussing the reason why this is strange that, included with last month's 7-bulletin release, a large majority of issues are coming from newer Windows OS versions. "That's kind of weird because newer OS versions are generally more secure."
As with every Security Update rollout, IT should prioritize the critical items first, but only apply after adequate testing has been completed.
While Microsoft has not issued any detailed information on the bulletin items, a heads-up on what to expect can be found in the company's Security Bulletin Advance Notification.