Microsoft Skips Patch Release, Leaves Nine Outstanding Bugs

Free Press Release
iPhone 3G SEO Local Dating Auto Insurance ...
 

Home | Submit Release | Features & Pricing | Success Stories | Blog | Journal | FAQ | Search | Members' Area

News Archive > 2007 > Mar > 9
 Premier News
With nine outstanding software bugs, Microsoft announced on Thursday afternoon that it won't be releasing any patches this month.
For_Immediate_Release:

March 9, 2007 (Press Release) -- With nine outstanding software bugs, Microsoft announced on Thursday afternoon that it won't be releasing any patches this month.

It's the first time the company hasn't gone through with its monthly Patch Tuesday release since September 2005. The security update was scheduled to be released Tuesday, March 13.

"There are many factors that impact the length of time between the discovery of a vulnerability and the release of a security update, and every vulnerability presents its own unique challenges," said a Microsoft spokesman in an e-mailed response to InformationWeek. "Microsoft continues to investigate potential and existing vulnerabilities in an effort to help protect our customers. Creating security updates that effectively and comprehensively fix vulnerabilities is an extensive process involving a series of sequential steps. All updates need to meet testing standards in order to be released. This ensures that our customers can confidently install these updates in their environment."

Johannes Ullrich, chief research officer at the SANS Institute and chief technology officer for the Internet Storm Center, says he's surprised that Microsoft won't release any patches this month since there are nine known vulnerabilities affecting Microsoft Office and Explorer.

"It's kind of funny with all the outstanding bugs today, and they have nothing to offer," he says. "I would expect some help to come."

Ullrich says the most critical known bug is in Microsoft Word 2000 and Word XP. The bug, which is being exploited, allows hackers to remotely control infected machines. Ullrich notes that the vulnerability has been publicly known since Feb. 9. "I would have expected it to be fixed this month," he adds.

Dan Hubbard, VP of security research at Websense, agrees with Ullrich that the Word vulnerability, which is a buffer overflow problem, is the most serious of all the outstanding Microsoft bugs. He says they've seen the bug being exploited in small, isolated cases. As serious as the flaw is, security experts say it hasn't been a widespread problem. Last month, InformationWeek reported that hackers used the then-unknown vulnerability to launch an attack against two employees at the same company.

With this vulnerability, a user has to open a malicious Office file attachment, such as a Word document, in an e-mail. If the file is opened, a Trojan or bot is downloaded onto the victim's computer, leaving it open for remote access. The infected machine then could be used as a zombie, or part of a botnet, to send out spam or launch denial-of-service attacks.

"It's not a widespread threat, but it's no picnic for the people being targeted," says Hubbard.

Paul Henry, VP of technologies with Secure Computing, says he's guessing that Microsoft found a problem within the patches themselves and decided to hold off for the month.

"I'm always concerned. Unpatched vulnerabilities out there create issues, and the bad guys take advantage to create havoc in our networks," Henry says. "I'd rather have something than nothing. It's a matter of how broken it is. If it introduces a lesser vulnerability, I'd go ahead with the patch. I'd rather have it be my choice."

In its advanced notification alert, Microsoft announced that it will release two high-priority, non-security updates through Windows Update and Software Update Services, and four high priority non-security updates through Microsoft Update and Windows Server Update Services.

Last month, Microsoft patched 12 vulnerabilities. Six of them were critical.

Author: Sharon Gaudin
Source: http://www.informationweek.com/


Email Print Download SPAM Submit to RestNews.COM

LEAVE A COMMENT
Title:


Message:
You can use following font styles to enhance your article. (No HTML tags.)
[large]sample[/large] sample
[b]sample[/b]sample
[i]sample[/i]sample
[color=#ff0000]sample[/color]sample
Your name:
Your email: (Please provide a valid email.)
Please read the number in the image:
Publisher: zyk06




Submit Press Release
IndustriesCountriesTags

Top Headlines More>>
Combo iPhone case & battery - Longer battery life
Mophie's last product of note was a combination iPod shuffle case/bottle-opener; of use to some, perhaps, but a little niche for my liking. They're following up with something far more useful, the mStation Mophie juice pack for iPhone - basically a soft-touch, non-slip case for the cellphone with a built in LiIon battery pack that adds an additional 250hrs of standby, 8hrs of talktime, 6hrs...
AN ANGEL OF MY OWN - The Ultimate Holiday Present
Composer E Rick Rinaldi and Anabelle Records Donate to Angel Foundation. AN ANGEL OF MY OWN is a Smart Holiday Gift Alternative Although not necessarily a consumer revolt, many families are opting out of children's gifts that carry the "Made In China" brand for this holiday season. News accounts of toy recalls, lead paint and other hazards have led some of the largest...
Would listening to Christmas Music make you rich?
Listening to Christmas Music brings the Tis the Season to be Jolly within everybody... And suddenly you will begin to attract everything... Okay. Then do this: 1. Eliminate ALL TV from your life. This means ALL; no Seinfield, no CSI , no American Idol, no news, no Sesame Street...ZILCH..NADA...NOTHING! ALL! 2. Eliminate ALL newspapers and \'news\' periodicals and magazines ...
The Ultimate Book of World Lists: The best and worst people, ideas, talents
The Ultimate Book of World Lists: The best and worst people, ideas, talents and accomplishments of our time (2 Volumes, 1,480 pages) by Maximillien de Lafayette. Unusual, explosive and the largest of its kind! Thousands of names and hundreds of lists from the United States and around the world in 300 fields. An unusual and completely different approach to lists of all lists. A...
Spy Sweeper Review - removing spyware
Stay safe from spyware at home!   Webroot Spy Sweeper - the most powerful, award-winning antispyware software. Webroot Spy Sweeper is a comprehensive solution for protecting your privacy and your computer from online security risks, including spyware, adware, and other potentially unwanted programs.  
123Together.com Offers Customers Early Access To Microsoft "Titan" As A Hosted Service
New "On Demand" Architecture Allows All SMBs To Immediately Take Advantage Of The Latest Customer Relationship Management Tool And Customize It To Their Needs. 123Together.com, a leading hoster of enterprise-class messaging and collaboration solutions such as Microsoft Exchange Server 2007, Windows SharePoint Services v3.0 and Microsoft Dynamics CRM 3.0, announced today that it is...
It's Going To Be Like MySpace On Steriods!!
Social networking meets network marketing with new FriendsWin network. Have you heard of the biggest thing on the internet today? It's FriendsWin.com! Friendswin is a social networking site being integrated with video to create amazing applications. Video dating, video resumes and video conferencing are only three...
China launches its first lunar orbiter
BEIJING -- Half a century after the Soviet Union beat the United States to outer space, China blasted off its first lunar orbiter Wednesday, catapulting the Asian nation onto the front lines of a new space race aimed at giving it bragging rights as a rising world power. The Chang'e 1 satellite, named after a mythical beauty who flew to the moon, lifted off under cloudy skies in...
Facebook to Improve Safety
Facebook Inc. will step up the policing of pornography, harassment and inappropriate behavior on its social networking site, settling a consumer fraud investigation by New York State Attorney General (AG). Facebook users can now report complaints about pornography, harassment or inappropriate contact either by clicking on links on the Web site or by sending email to the abuse@facebook.com...

Sitemap | All News | Daily | Weekly | Monthly | Tags | Industries | Countries | RSS | Add URL | Contact Us

Free Press Release All press release information on this site, including free press release and premier press release, is solely based on what our users submit. Free-Press-Release.com disclaims that any right and responsibility for the information goes to the user who submit the press release. Some press release may be confusing without additional explanation. You should contact the provider with any questions about the information presented. In case some press release damages your benefits or violate your rights in any way, please contact us and we'll remove it immediately.
  • Press Release
  • Pub Gratuite