This page permanently redirects to gemini://gemini.techrights.org/2008/12/11/microsoft-patch-cycle/.
Posted in Microsoft, Security, Windows at 6:28 am by Dr. Roy Schestowitz
Microsoft’s handling of security is a cyclic routine that goes like this:
Many flaws get reported, accumulated, and then mostly ignoredAttacks on the unpatched flaws begin, so Microsoft ‘kindly’ bothers to work on patches in a rushPatch Tuesday arrives and Microsoft delivers a slew of patches (occasionally delivering nothing critical for bragging rights in the press, only to deliver a massive number of critical patches the following month, i.e. deferral)Patches arrive too late, after many servers and desktop have already been hijackedA number of zero-day flaws emerge, some of which exploiting vulnerabilities Microsoft has been aware of for a long timePatches turn out to be dysfunctional and consequently many computers are left out of servicesMicrosoft reworks the patches and then delivers a patch to the broken patchesRepeat (1)
This month was no exception. Microsoft delivered half a dozen “critical” patches (usually meaning that the vulnerability they patch enables crackers to seize full control of a to-be-compromised machine).
Appended below are reports from the past couple of days alone. The lies need to end because everyone suffers. █
=> lies | need | to | end | because | everyone | suffers
____ [1] Another Microsoft Bug Revealed on Huge Patch Day
=> ↺ Another Microsoft Bug Revealed on Huge Patch Day
Along with its biggest patch release in five years, Microsoft warned on Tuesday of another potentially dangerous vulnerability in its software.
The problem lies within the WordPad Text Converter for Word 97 files, Microsoft said in an advisory.
The systems affected include Windows 2000 Service Pack 4, Windows XP Service Pack 2, Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2, Microsoft said. XP Service Pack 3 and the Vista operating systems are not affected.
[2] Two new zero-day exploits dent Microsoft’s Patch Tuesday
=> ↺ Two new zero-day exploits dent Microsoft’s Patch Tuesday
Microsoft’s Patch Day delivered eight updates, but has been overshadowed by newly discovered zero day holes, which are apparently not closed by the new updates.
[3] New Web Attack Exploits Unpatched IE Flaw
=> ↺ New Web Attack Exploits Unpatched IE Flaw
As Microsoft readies its latest set of security updates, online attackers have begun exploiting a new flaw in the company’s Internet Explorer (IE) browser.
[4] Third Zero Day exploit appears
=> ↺ Third Zero Day exploit appears
Microsoft has confirmed it is investigating another zero day exploit.
[5] Security vulnerability found in MS SQL Server 2000
=> ↺ Security vulnerability found in MS SQL Server 2000
SEC Consult say Microsoft has been aware of the problem since April this year. Despite the promise of a patch by September, a release date for the patch remains uncertain.
Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
Permalink Send this to a friend
=> Permalink | ↺ Send this to a friend
=> Techrights
➮ Sharing is caring. Content is available under CC-BY-SA.
text/gemini;lang=en-GB
This content has been proxied by September (ba2dc).