Microsoft Promises Huge Patch Day Next Week

Slates 11 updates for Windows, IE, Active Directory, Office and Host Integration Server.

By Gregg Keizer on Thu, October 09, 2008
Tweet it!
Email
Digg
Share this article
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

ComputerworldMicrosoft Corp. today said it will issue 11 security updates next week—the same number it shipped in August when it pushed out the most patches in 18 months—to fix bugs in Windows, Active Directory, Internet Explorer (IE), Office and Host Integration Server.

Four of the 11 updates will be labeled "critical," Microsoft's highest threat ranking, with six pegged "important," the next-lowest rating, and one tagged as "moderate."

As is Microsoft's practice, it released only the most general information about the upcoming security patches in the advance notification it posted Thursday. Among the details that the company provided are the affected software, the severity of the security problem and the components involved.

Seven of the 11 updates will address vulnerabilities that Microsoft acknowledged can be used to execute remote code, a description that generally means hackers could exploit those vulnerabilities to inject their own malicious code into vulnerable PCs, often by convincing users to open a file attachment or tricking them into visiting a rogue Web site. All four of the critical updates were marked with Microsoft's "Remote Code Execution" label, as were three of the important bulletins.

Bugs in Active Directory, IE, Excel and Microsoft Host Integration Server were all tagged critical.

The Active Directory fix will apply only to Windows 2000 Server, said Microsoft, which has patched the component several times, most recently in June when it fixed a broader problem in validating client LDAP requests.

On the other hand, the patch for Host Integration Server (HIS) is a first for that software, a little-known enterprise product that connects Windows-based networks to the IBM mainframe and AS/400 systems. HIS 2000, HIS 2004 and HIS 2006 are all affected, said Microsoft.

Based on the versions affected, the Excel update will likely patch a file format problem; both Windows and Mac editions of the spreadsheet program will have to be patched, said Microsoft. When that has happened in the past, the update has usually addressed file format bugs.

The IE patch, meanwhile, will fix flaws rated critical in IE5 and IE6, but which Microsoft ranked as only important for the newer IE7. According to Danish bug tracker Secunia, which lists several vulnerabilities in IE that need attention, the most-pressing problem is a cross-domain scripting bug in IE6 reported more than three months ago.

Other updates, including all six marked important, will address bugs in various versions of Windows; the one bulletin labeled moderate affects only Office XP Service Pack 3 (SP3).

In a related note, Microsoft said last month that Tuesday's updates would be the last for Office 2003 SP2; after next week, the company will only support that version of Office as Service Pack 3.

Microsoft will release the 11 security updates at approximately 1 p.m. EST on Oct. 14.

Microsoft

Get up to speed on mobile security.

Learn More »
Loading...
Most Recent Security Stories
The path to creating a secure application begins by rigorously testing source code for all vulnerabilities and ensuring that use of the application does not compromise or allow others to compromise data privacy and integrity.
The reasons for outsourcing application development are many and varied. Outsourcing can be a cost effective and efficient solution to the demand for new and specialized applications in todays Internet-based marketplace. It is absolutely critical, however, that the team responsible for evaluating the outsourced application makes security one of its principal criteria prior to acceptance of each release.
The path to creating a secure application begins by rigorously testing source code for all vulnerabilities and ensuring that use of the application does not compromise or allow others to compromise data privacy and integrity.
Enterprises understand the importance of securing web applications to protect critical corporate and customer data. What many dont understand, is how to implement a robust process for integrating security and risk management throughout the web application software development lifecycle.
Watch an online demo of iPrism and you'll get a $20 Amazon gift card as our way of saying thanks.
Online fraud is a non-stop threat to organizations around the globe, and cybercriminals have no intention of slowing down the pace. Also, global are likely to have an impact on the evolution of cybercrime. Read this special online fraud report for information about the latest online fraud trends and what to expect and prepare for in the future.
Key IT Security & Authentication Concerns for 2010
Data protection is a bigger challenger for small and midsize businesses. You need to protect sensitive data, but la...
Privacy and Data Protection Practices
Moderated by CSO Publisher, Bob Bragdon, hear from this esteemed panel as they share practical approaches to simpli...
Avoid common pitfalls and learn strategies for ensuring a successful PCI audit from information security and compli...
Protecting critical data is now the imperative at most every organization. As more and more laws are passed and reg...
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Sponsored Links

Simplifying Risk Management: Is Your Company Measuring Up?

Attend Microsoft's Windows 7 Virutal Event for a change to win a Microsoft Zune HD. Register Now!

Ready to create safe, business class social networking tools? View Now

Let Progress Software help your business make progress.

Register for more Windows Enterprise Webcasts today.

Entrust IdentityGuard  Strong Authentication for your Enterprise

Supercharge Your End Users with Desktop Virtualization

Take the Netezza TwinFin TestDrive!

Best Practices to Reduce IT Operational Costs

Maximizing efficiencies with unified communications.

Taking the Service Desk to the Next Level

Getting ready to upgrade to Windows 7? Attend Microsoft's Virtual Event on 4/22 for all the tools you'll need. Register Now!

Read report on how to improve decision making with business analytics.

Dynamic Virtual Client: Whats in store for client technology going forward?

The ISP that focuses exclusively on information security? SecureWorks.

Does your IDS really work? Find out with a free Endace Audit

CA ARCserve r12.5 is More Than Backup! Download Trial Version Today

Enterprise search helps employees get more done. Get the facts from Google.

Real-world testing ranks Trend Micro #1 against malware. See results.

Dark Fiber from Sunesys Save on Unlimited Bandwidth with Fixed Costs.

Trend Micro ranked #1 against real-world malware. Read more.

How Healthcare CIOs Achieve a High-Performance Emergency Department

Webcast: Solve Your Data Visualization Needs with Open Source BI

Webcast: Delivering the Enterprise-Ready Cloud

Ensure cost effective application delivery. Learn More.

Trend Micro ranked #1 against real-world malware. Read more.

March 31st Webcast: "Product Development and the Cross-Functional Team"

Get to know Supermicro. Business-optimized server solutions.

Google Webinar: Why Cloud-Based Security and Archiving Make Sense

HP pays back. Trade in your old printer and get up to $1000

Counting Up the End User Benefits of Desktop Virtualization

Build a smart, practical path to the internal cloud.

Verint Systems. Discover the Power of Intelligence in Action"

Efficiency goes up. Costs come down.

Achieving Business Agility with Application Grid

Seven Ways ITIL Can Help You in an Economic Downturn

Midsized company CIOs and experts connect at infoBOOM!

Core" i5 vPro" Processor: Control meets cost savings in the most intelligent PC processors ever!

Article: The Dynamic Virtual Client offers thin client advantages with rich client user experience & mobility.

Manage limitless content todayread EMCs 15-minute guide to ECM.

HP Exstream. Get a Free Document Assessment for Financial Services.

Webinar: Jump-start your in-house e-discovery with Ringtail QuickCull from FTI Technology

See why ShoreTel is named best overall VoIP provider by Nemertes Research

Turn your desk phone and mobile phone into one with Sprint Mobile Integration.

Stay informed with custom newsletters from Tech Dispenser

Get ready for your Windows 7 upgrade at this live, virtual event. Register Now!

Selecting the Right Reporting Technology

An IT Leadership Action Plan for the Economic Recovery

Consolidate data centers and lower IT service costs. Learn How.

WAN optimization techniques significantly improve application performance. Read More.

Resource Center