Patch Tuesday heads-up: 17 bulletins, 64 vulnerabilities

Summary: Microsoft is planning a monster Patch Tuesday next week: 17 bulletins with fixes for 64 documented vulnerabilities across a wide range of Windows products.

Microsoft is planning a monster Patch Tuesday next week:  17 bulletins with fixes for 64 documented vulnerabilities across Microsoft Windows, Microsoft Office, Internet Explorer, Visual Studio, .NET Framework and GDI+.

According to Microsoft's advance notice, 9 of the 17 bulletins will be rated "critical," the company's highest severity rating.

This month's batch of patches, due at 1:00 pm Eastern on Tuesday April 12, will include an Internet Explorer browser update that fixes a pair of publicly known security problems:

This month we'll be closing some issues that Microsoft has already previously spoken to, including the SMB Browser (Critical) issue publicly disclosed Feb. 15. Microsoft assessed the situation and reported that although the vulnerability could theoretically allow Remote Code Execution, that was extremely unlikely.  To this day, we have seen no evidence of attacks.

We are also planning a fix for the MHTML vulnerability in Windows, rated Important. We alerted people to this issue with Security Advisory 2501696 (including a Fix-It that fully protected customers once downloaded) back in late January. In March, we updated the advisory to let people know we were aware of limited, targeted attacks.

There is no word on whether this IE update will include a fix for the multiple bugs used in the winning CanSecWest Pwn2Own exploit.

All versions of Windows are affected by this batch of updates, including the newest Windows 7.

Topic: Security

Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.

Talkback

55 comments
Log in or register to join the discussion
  • It would be nice if, for once...

    everyone would agree that finding and fixing vulnerabilities is a good thing, and that no software is perfect, and just leave it at that.
    msalzberg
    • Closing stable doors is fine...

      @msalzberg<br>... just so long as the horses didn't bolt weeks earlier ;-).
      Zogg
      • What does this mean?

        @Zogg: [i]Closing stable doors is fine just so long as the horses didn't bolt weeks earlier.[/i]

        Are there any specific "horses" you're referring to?
        ye
      • RE: Patch Tuesday heads-up: 17 bulletins, 64 vulnerabilities

        @ye
        Ever heared of the term "idium"?

        What he means in this case is "just as long as the vulnerabilities haven't gone wild for a long period".

        Guessing english is your second language :D
        MrElectrifyer
      • RE: Patch Tuesday heads-up: 17 bulletins, 64 vulnerabilities

        @MrElectrifyer

        "Ever heared[sic] of the term "idium[sic]"?"

        Guessing english isn't your native tongue, either.
        msalzberg
      • Either MrElectrifyer's reading comprehension is much better than yours

        @Ye
        Or you were spoiling for a fight. Again.
        Possibly even both.
        Zogg
      • Did you happen to notice the quotes?

        @MrElectrifyer: [i]Ever heared of the term "idium"?[/i]
        ye
      • See my response to MrElectrifyer

        @Zogg: <i>Or you were spoiling for a fight. Again.<br>Possibly even both.</i><br><br>
        What I was "spoiling" (see, there are those quotes again) for was you to explain what you meant with your post as it isn't clear to me what you're trying to say.
        ye
      • See MrElectrifyer's response to you.

        @Ye
        MrElectrifyer understood my post: a general comment on the time interval between bugs being found and patches being provided.

        I had originally planned to suggest that the horses may not have bolted during that time, but may have been replaced by wooden ones instead. And you may contemplate the extra implications of <i>that</i> at your leisure... ;-)
        Zogg
      • You comment doesn't make sense.

        @Zogg: [i]a general comment on the time interval between bugs being found and patches being provided.[/i]

        That phrase is used [i]after[/i] some event has happened. To my knowledge there has been no event, hence my question to you.
        ye
      • @Zogg

        @Zogg

        Nice, very nice! Although you'd be alright if you have a daughter called Cassandra! ;-)
        DevJonny
      • Oh, the irony!!!!

        @Ye

        <i>"That phrase is used after some event has happened."</i>

        After the horses have bolted, eh :D ??? Don't you think it's <i>always</i> worth patching sooner rather than later? Or have you forgotten the sense of the original post?
        Zogg
      • Yes, I do.

        @Zogg: [i]Don't you think it's always worth patching sooner rather than later? Or have you forgotten the sense of the original post?[/i]

        This still doesn't explain your original post.
        ye
      • RE: Patch Tuesday heads-up: 17 bulletins, 64 vulnerabilities

        @MrElectrifyer<br>Never heard of the term "idium". (Never heard of the word "heared", either. Perhaps you're referring to the word "Idiom"? (Spelled like "idiot"...just replace the "t" with an "m".<br>Guessing english isn't your language at all.
        brentbrandes
      • Patch Tuesday.... Weld? Huh? Where am I?

        @Zogg <br>The daughter Cassandra? Idium? Wooden horses?<br>Apart from Illium being mis-spelled, I fear I may have wandered into a forum on Homeric literature! <br> <br>I hate to spoil the ending, but- the Trojans lost. <br>Damn, the Greeks had powerful AV products back then!<br>And please don't close those (Augean) stable doors just yet- Hercules is still busy cleaning 'em out!
        PercySludge
      • Percy, I don't blame you for being confused

        @PercySludge
        Someone (who shall remain nameless) has misread / misunderstood some semi-serious banter, and now the point of the original post and my reply to it has been completely buried. Someone else misspelling "idiom" has only added to the confusion...

        I fear that only Hercules could possibly unearth the point of this thread now, but seeing as he's still busy cleaning out the Augean stables I suggest we let the thread rest instead.
        Zogg
    • RE: Patch Tuesday heads-up: 17 bulletins, 64 vulnerabilities

      @msalzberg <br><br>What are you talking about? Linux and Mac OS X are perfect!!!<br><br>/sarcasm_bit_on
      betelgeuse68
      • RE: Patch Tuesday heads-up: 17 bulletins, 64 vulnerabilities

        @betelgeuse68

        The funny thing to me is that Linux updates (at least with the Ubuntu distro) are sent out far more frequently than Windows Updates....the last time I used Ubuntu it seemed that there were new updates to download every time I turned it on....but you point this out to Linux nuts and they say 'Linux is a work in progress'......somehow that's a good enough excuse for Linux...but not Windows.
        Doctor Demento
      • RE: Patch Tuesday heads-up: 17 bulletins, 64 vulnerabilities

        @betelgeuse68 Thanks for the laugh! And it's good you added that /sarcasm_bit_on to your comment because otherwise a lot of people would've thought you were actually being serious.
        xplorer1959
      • RE: Patch Tuesday heads-up: 17 bulletins, 64 vulnerabilities

        @betelgeuse68
        Oh, I was going to post something similar.

        I heared Macs don't have any problems with viruses so I think they must be the best then. Also, have you heard, the next version will let you run programs full screen! Take that Microsoft!
        jamsdwy