Data Storage Today

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
News & Information for Data Storage Professionals
Monday, September 6th 
Home
Storage Hardware
Storage Software
Storage Networks
Storage Trends
Next-Gen Storage
Data Security
DST Press Releases
 
Free Newsletters
Top CIO News
 
Mobile Tech Today
 

Advertisement
Data Security

Patch Tuesday Will Be Biggest Ever with 13 Bulletins

Patch Tuesday Will Be Biggest Ever with 13 Bulletins
October 9, 2009 9:17AM

Bookmark and Share
Next week's Patch Tuesday will be Microsoft's biggest ever with 13 bulletins to address 34 security vulnerabilities. Eight of the Microsoft bulletins are rated critical. The patches cover Microsoft Office, SQL Server, Internet Explorer, developer tools, and all currently supported versions of Windows. The patches will keep IT departments busy.


Microsoft is preparing for its biggest-ever Patch Tuesday -- and analysts said IT Relevant Products/Services administrators should do the same. The software giant will issue 13 bulletins to address 34 security vulnerabilities across a wide range of products. Eight of the bulletins come with critical ratings, including two for vulnerabilities that are already being exploited.

The patches cover Office, SQL Server, Internet Explorer, and Microsoft developer tools, as well as all currently supported versions of Windows, including the yet-to-be released Windows 7. The previous largest Patch Tuesdays were 12 bulletins in October 2008 and November 2007.

Avoiding IT Headaches

"Microsoft is releasing a heavy load of patches to organizations next Tuesday with eight critical and five important vulnerabilities," said Paul Zimski, vice president of market strategy for Lumension. "Overall, the advanced bulletin from Microsoft further illustrates the importance of a strong patching solution, as IT administrators will spend a lot of extra time patching this month if they don't have a proper process in place."

Zimski pointed to several standout bulletins coming Tuesday. One he highlighted is Bulletin 13, which is labeled as critical. Zimski said this bulletin raises a red flag because it affects a large number of operating systems, core services, and applications.

"It is most likely a low-level vulnerability shared within the operating system itself that needs to be fixed," Zimski said. "Before deploying this patch into production environments, however, it will be important to test it vigorously to ensure services are not impacted by unexpected results."

Drive-By Malware

Bulletin 5 presents an increased threat for what is typically called drive-by malware -- which users download without understanding the consequences or browser exploitation without the user's knowledge.

Zimski sees an increased threat because the bulletin concerns the most current versions of Internet Explorer -- versions 7 and 8 -- on multiple operating-system platforms. That, Zimski said, makes this vulnerability a prime target for malware writers and malicious web operators.

"On Tuesday, organizations should also pay close attention to the details listed in Bulletins 7 and 9, two 'important' vulnerabilities, to determine how critical they are within their business environments," Zimski said.

Zimski said vulnerabilities involving spoofing and elevation of privilege should raise an alarm for IT administrators as they can potentially have a big impact on verifying trusted destinations and controlling user privileges. Those are things over which IT never wants to lose control.

In addition to these bulletins, Zimski said all the critical vulnerabilities are labeled as remote code execution across a broad variety of Windows platforms. They will require a restart.

Tell Us What You Think
Comment:

Name:

Advertisement



 Data Security
1. Consumer Watchdog Attacks Google
2. Spammers Take Over Apple's Ping
3. VMware Reinforces 'IT as a Service'
4. Hackers Invade iTunes Accounts
5. Security Threats a Record, IBM Says


advertisement


 Most Popular Articles
1. Dell Buys Virtualization Storage Provider 3PAR
2. Patch Fixes SMB Attack That Could Come from Within
3. Intel Will Acquire McAfee To Secure Online Computing
4. Apple Issues iOS Patch To Block Hacker Bonanza
5. Intel's Deal for 'Buggy Whip' Maker McAfee Will Impact IT

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  HP vs. Dell: Behind the Showdown
  Consumer Watchdog Attacks Google
  Spammers Take Over Apple's Ping
  HP Wins 3PAR at $2.4B as Dell Quits
  Data Storage Advances Are Looming

 Technology Marketplace
Compliance
Stand out from other IS Professionals and increase your earning potential.®.
Manage limitless content today—read EMC’s 15-minute guide to ECM.
 
Data Storage
Isilon scale-out storage is simple. Simple is smart.
 
Digital Life
IT PROS: Receive $10 in rewards to complete a 15 min. survey.
 
Enterprise I.T.
Stand out from other IS Professionals and increase your earning potential.®.
IT PROS: Receive $10 in rewards to complete a 15 min survey.
 
Enterprise Software
Manage limitless content today—read EMC’s 15-minute guide to ECM.
 
Mobile Gadgets
White Paper The Motorola ES400: Desktop power in a pocket-sized device
 
Mobile Industry News
The Motorola ES400: Desktop power in a pocket-sized device.
 
Mobile Phones
The Motorola ES400: Desktop power in a pocket-sized device.
 
Navigation
Data Storage Today
Home/Top News | Storage Hardware | Storage Software | Storage Networks | Storage Trends | Next-Gen Storage | Data Security
DST Press Releases
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 Data Storage Today. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.