ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

MS Patch Tuesday heads-up: Critical Windows update on deck

By | May 5, 2011, 10:36am PDT

Summary: Microsoft plans to have a quiet Patch Tuesday this month: Just two bulletins covering security vulnerabilities in the Windows operating system and Office productivity suite.

Microsoft plans to have a quiet Patch Tuesday this month:  Just two bulletins covering security vulnerabilities in the Windows operating system and Office productivity suite.

According to an advance notice from Redmond, the Windows update will be rated “critical” because of the risk of remote code execution attacks.  This patch only affects Windows Server 2003, Windows Server 2008 and Windows Server 2008 R2.

The Microsoft Office patch will carry an “important” rating and will also cover flaws that can be exploited in remote code execution attacks.

The patches are expected to be released on May 10, 2011 at 1:00 PM Eastern.

Microsoft also announced plans to modify its Exploitability Index to provide more details for Windows users running the newest software versions.

The Exploitability Index assesses the likelihood of functional exploit code being developed for a particular vulnerability. By providing the index information month over month, we’re helping customers prioritize the security updates that matter to them. The Exploitability Index will continue to provide an aggregate exploitability rating across all affected products, and the improvements made to Exploitability Index will now offer additional information to help customers prioritize bulletins, specifically for the most recent platforms, e.g. Windows 7 Service Pack 1 and Office 2010.

The changes effectively means that Microsoft will split out the Exploitability Index into a rating for the most recent version of the software, and an aggregate rating for all older versions.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues.

Disclosure

Ryan Naraine

The most important disclosure is of my employment with Kaspersky Lab as a member of the global research and analysis team. Kaspersky Lab is a global company specializing in anti-malware and secure content management technologies. I do not own stocks or other investments in any technology company.

Biography

Ryan Naraine

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues. He is currently security evangelist at Kaspersky Lab, an anti-malware company with operations around the globe. He is taking a leadership role in developing the company's online community initiative around secure content management technologies.

Prior to joining Kaspersky Lab, Ryan was Editor-at-Large/Security at eWEEK, leading the magazine's and Web site's coverage of Internet and computer security issues and managing the popular SecurityWatch blog, covering the daily threats, vulnerabilities and IT security technologies. He also covered IT security, hacker attacks and secure content management topics for Jupiter Media's internetnetnews.com.

Ryan can be reached at naraine SHIFT 2 gmail.com. For daily updates on Ryan's activities, follow him on Twitter.

13
Comments

Join the conversation!

Just In

RE: MS Patch Tuesday heads-up: Critical Windows update on deck
talih Updated - 12th Aug
Great!!! thanks for sharing this information to us!
sesli chat sesli sohbet
0 Votes
+ -
What's that?
facebook@... 5th May 2011
This post is several hours old and no "{Apple|Google} does it better" post yet?
0 Votes
+ -
It's because
Michael Alan Goff 5th May 2011
-Google doesn't do Desktop OS updates (no desktop OS)
-Apple's updates are slow, vulnerabilities sitting unfixed for a long time
@facebook@...

Apple does do it "better". It is just that ZDNet doesn't tell us about it:

http://www.computerworld.com/s/article/9196118/Apple_smashes_patch_record_with_gigantic_update

And yes that is correct, ZDNet didn't even bother to tell anyone about that patch. Not a single article.
Micro$oft swiss cheese as usual.
0 Votes
+ -
And Blind Obedience for the epic first troll post.

He deserves some sort of award. Honestly.
0 Votes
+ -
RE: MS Patch Tuesday heads-up: Critical Windows update on deck
Michael Alan Goff Updated - 5th May 2011
BAD WIFI
@blind obedience

Yes, let's compare MS's "swiss cheese" OS with this stunner:

http://www.computerworld.com/s/article/9196118/Apple_smashes_patch_record_with_gigantic_update

The only reason people think OSX is more secure is because that patch release was never even mentioned on ZDNet. At all. No wonder some people are so clueless...
0 Votes
+ -
Yet another achievement by 2011
MrElectrifyer Updated - 5th May 2011
Gush, you really gotta love this year; it sure has been shinning more and more light in the eyes of several noobish UNIX derivativ fanboys. happy

Usually just within a couple of hours after an article about Microsoft Security updates, I read several noob talks about how Unix derivativ OSs are more secure silly

Maybe I'm just here too early this time plain Will be keeping an eye on this article for some noobish fanboy talks wink
Keep it up 2011, there are still millions of hard headed noobish fanboys out there that still require the truth to be shined in their eyes; No man-made software/OS is immune to malware nor nasty hackers happy
@MrElectrifyer
" Usually just within a couple of hours after an article about Microsoft Security updates, I read several noob talks about how Unix derivativ OSs are more secure silly

Maybe I'm just here too early this time plain Will be keeping an eye on this article for some noobish fanboy talks wink

Does this help...
Unix/Linux is just simply the most secure O.S. in the WORLD!!! No one ever tries to hack, crack, or write malicious code to attack it since it is impenetrable! Like IRON!! Just can't be hacked, cracked, or infected!

No do you feel better? - LOL!!!
why they don't do anything remote code execution attacks
Is this news?
And the FBI still has to send out "kill" commands to all of these Windows, infected, zombie PC's. Nothing will save Windows from it's ultimate demise.
Great!!! thanks for sharing this information to us!
sesli chat sesli sohbet

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix