Microsoft pulls four planned patches

By Joris Evers, CNET News.com
Monday, January 08, 2007 11:05 AM

Microsoft has pulled four bulletins from its announced list of Patch Tuesday fixes, but did not specify why it was backpedaling on the security releases.

It now plans to issue four security bulletins on Tuesday, rather than the eight originally announced, the software giant said last week in an updated notice on its Web site.

Three bulletins will contain fixes for Office, at least one of which will be rated "critical," Microsoft said. Critical vulnerabilities typically can allow a worm to spread or allow a Windows system to be fully compromised with minor or no interaction from the person using it. The fourth bulletin, for Windows, is also tagged critical.

On Friday, Microsoft listed eight bulletins it intended to issue this week in its monthly patch cycle. It appears to have pulled two bulletins for Windows, one for Windows and Visual Studio and one for Windows and Office. These patches will now likely be released on a future Patch Tuesday.

The Redmond, Wash.-based software giant did not provide any explanation for pulling the bulletins only a few days before their scheduled release. "There are many factors that impact the release of a security update, and every vulnerability presents its own unique challenges," a Microsoft representative said in an e-mailed statement.

The company does not specify ahead of time which security vulnerabilities are addressed by its patches. As a result, it's unknown what security holes will now be left without a fix. eEye Digital Security, on its Zero-Day Tracker Web site, lists eight zero-day vulnerabilities that Microsoft still has to address, with four each in Office and Windows.

Zero-day vulnerabilities are security holes that have been publicly disclosed without a fix being available. In some cases, exploit code may be available for such a flaw, and there may be cyberattacks that take advantage of it. However, Microsoft's patches often address vulnerabilities that have not been publicly disclosed.

The company sometimes deviates from the Patch Tuesday advance notification. Last month, for example, it issued one more security bulletin than it had said it would. It has also dropped bulletins, citing quality issues. However, it has never before pulled four bulletins.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Use shades of gray to enhance scale in Excel

Microsoft Office Suite

Excel's palette is generous, but don't throw buckets of pigment all over your spreadsheets just because you can.


Read more »



Ultimate 2012 recovery site: the moon

Blog thumbnail

Have you seen the disaster movie "2012"? A friend from Control Risks and I did, and we reluctantly concluded we wouldn't be able to write off the cost of our..... by Nathaniel Forbes

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web