Microsoft plans monster security update for next week

Microsoft will issue 16 security updates on Tuesday, the most in more than three years, to patch Internet Explorer, Windows, Office, Exchange Server and SharePoint Server.

Microsoft today said it will issue 16 security updates on Tuesday, the most in more than three years, to patch Internet Explorer (IE), Windows, Office, Exchange Server and SharePoint Server.

The 16 "bulletins," as Microsoft calls its updates, listed in today's advance notice were nearly double the previous 2014 record of nine set in May and August, trumped 2013's record of 13, and came within an ace of the all-time 17 last set in April 2011.

Russ Ernst, director of product management with security firm Lumension, called November's slate "whopping" in an email today, while Jon Rudolph, senior software engineer at Core Security, christened it "overwhelming."

Five of the 16 were pegged "critical," Microsoft's most serious threat ranking. Nine were tagged "important," the next step down in the four-step scoring system, while two were labeled "moderate."

A quintet were identified as fixing vulnerabilities that, if exploited, could result in "remote code execution," meaning that successful hackers could hijack a system and install malware on the machine. Seven others will patch less dire "elevation of privilege" bugs.

As is now rote, Microsoft will patch all supported versions of its IE browser, from the almost-retired IE6 on Windows Server 2003 to the newest IE11. The fix for IE on Windows' client editions -- Vista, Windows 7 and Windows 8/8.1 -- was ranked critical for IE7, IE8, IE9, IE10 and IE11.

Microsoft did not put a number to the individual IE vulnerabilities it will patch, but in the last five months the company has quashed 161 bugs in the browser, or an average of 32 each month. The largest number of IE flaws fixed in a single month during that stretch was 60 in June, but September (with 37) and August (26) weren't far behind.

Other critical updates will tackle vulnerabilities in various flavors of Windows, including the intriguing Bulletin 5, which affects only the server operating systems. Microsoft said that the one or more bugs set for quashing by Bulletin 5 were not present in the client editions, but that they would be updated nonetheless to provide "additional defense-in-depth hardening" as protection against similar vulnerabilities that may pop up in the future.

A pair of the important updates will address vulnerabilities in SharePoint Server 2010 and Exchange Server 2007, 2010 and 2013. Fixes applied by those updates will deal with elevation of privilege flaws, and may require restarting the servers, often a dicey deal for IT staffs as both SharePoint and Exchange -- but especially the latter -- are mission-critical systems that cannot be offline for any but the very shortest stretches.

"Exchange server patching is always tricky because the systems are mission critical and often deployed on the perimeter," agreed Ross Barrett, senior manager of security engineering at Rapid7, in an email. "Administrators will have to balance the risk of exploit with their perceived exposure and their tolerance for downtime."

Microsoft will release the 16 updates on Nov. 11 around 10 a.m. PT (1 p.m. ET).

Join the CSO newsletter!

Error: Please check your email address.

Tags Malware & VulnerabilitiesLumensionantispamMicrosoftsecurity

More about LumensionMicrosoftRapid7

Show Comments

Featured Whitepapers

Editor's Recommendations

Solution Centres

Stories by Gregg Keizer

Latest Videos

  • 150x50

    CSO Webinar: The Human Factor - Your people are your biggest security weakness

    ​Speakers: David Lacey, Researcher and former CISO Royal Mail David Turner - Global Risk Management Expert Mark Guntrip - Group Manager, Email Protection, Proofpoint

    Play Video

  • 150x50

    CSO Webinar: Current ransomware defences are failing – but machine learning can drive a more proactive solution

    Speakers • Ty Miller, Director, Threat Intelligence • Mark Gregory, Leader, Network Engineering Research Group, RMIT • Jeff Lanza, Retired FBI Agent (USA) • Andy Solterbeck, VP Asia Pacific, Cylance • David Braue, CSO MC/Moderator What to expect: ​Hear from industry experts on the local and global ransomware threat landscape. Explore a new approach to dealing with ransomware using machine-learning techniques and by thinking about the problem in a fundamentally different way. Apply techniques for gathering insight into ransomware behaviour and find out what elements must go into a truly effective ransomware defence. Get a first-hand look at how ransomware actually works in practice, and how machine-learning techniques can pick up on its activities long before your employees do.

    Play Video

  • 150x50

    CSO Webinar: Get real about metadata to avoid a false sense of security

    Speakers: • Anthony Caruana – CSO MC and moderator • Ian Farquhar, Worldwide Virtual Security Team Lead, Gigamon • John Lindsay, Former CTO, iiNet • Skeeve Stevens, Futurist, Future Sumo • David Vaile - Vice chair of APF, Co-Convenor of the Cyberspace Law And Policy Community, UNSW Law Faculty This webinar covers: - A 101 on metadata - what it is and how to use it - Insight into a typical attack, what happens and what we would find when looking into the metadata - How to collect metadata, use this to detect attacks and get greater insight into how you can use this to protect your organisation - Learn how much raw data and metadata to retain and how long for - Get a reality check on how you're using your metadata and if this is enough to secure your organisation

    Play Video

  • 150x50

    CSO Webinar: How banking trojans work and how you can stop them

    CSO Webinar: How banking trojans work and how you can stop them Featuring: • John Baird, Director of Global Technology Production, Deutsche Bank • Samantha Macleod, GM Cyber Security, ME Bank • Sherrod DeGrippo, Director of Emerging Threats, Proofpoint (USA)

    Play Video

  • 150x50

    IDG Live Webinar:The right collaboration strategy will help your business take flight

    Speakers - Mike Harris, Engineering Services Manager, Jetstar - Christopher Johnson, IT Director APAC, 20th Century Fox - Brent Maxwell, Director of Information Systems, THE ICONIC - IDG MC/Moderator Anthony Caruana

    Play Video

More videos

Blog Posts