Friday | 10 July, 2009
CSO
Microsoft patches nine bugs in Windows, IE, Word
But it spiked one update at the last minute for the second consecutive month
Gregg Keizer (Computerworld) 10/10/2007 08:21:09

Also of interest, said Storms, was what wasn't released this week.

For the second consecutive month, Microsoft pulled an update from the list it had released just five days before. This cycle it dropped an update that was to have patched Windows 2000 SP4 and all versions of Windows Server 2003. Last week, Storms speculated that the patch targets may indicate a vulnerability in a service run only on servers. "If that is in fact the case," he said, "then the fix is probably much more complicated and the vulnerability impacts more core code. That means Microsoft would expend much more quality assurance around it, which might explain the delay."

Although Microsoft did not notify users of its decision to yank a bulletin -- something it's done in the past, either by posting on the Microsoft Security Response Center blog or by revising the advance notification alert -- Symantec knew one was going to be spiked. In an alert issued last week to customers of its DeepSight threat network, Symantec said only six updates would be released this week.

Symantec declined to say how it knew of the decision, or whether it was given prior notice by Microsoft. Cross also had no comment when asked if IBM's X-Force knew beforehand that the seventh update had been withdrawn.

In a statement attributed to Mark Miller, director of security response communications at Microsoft, and forwarded to Computerworld by the company's public relations team, Microsoft said its policy is not to revise the advance notification when minor changes are involved. "When significant changes are made to the release, Microsoft will normally notify customers through a re-release of the [advanced notification] and all accompanying communications," Miller said.

Microsoft's monthly updates are available via the Microsoft Update and Windows Update services, as well as through Windows Server Update Services (WSUS).

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Enter the fully qualified URL, eg. http://www.example.com/
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Syndicate content
 
Whitepaper

Extensible Threat Management

Unified threat management (UTM) spawned a new era of IT security. The promise of these integrated security appliances proved to be an exceptional and efficient way of securing commercial networks. However, businesses today face an inflection point, dictated by changing market trends and new technologies that demand more of today’s UTM. Hence the need is for eXtensible threat management (XTM) solutions, the next generation of UTM appliances.

Sponsored Links