Feeds

MS pulls upcoming Windows security patch

Quality of mercy

Website security in corporate America

Microsoft has pulled plans to release a critical Windows security patch on Tuesday citing quality concerns as the reason behind the late withdrawal. Last Thursday Microsoft announced its intent to release a solitary patch in September as part of its monthly patch cycle but by Friday afternoon the software giant had second thoughts prompting it to pull the planned release.

"Late in the testing process, Microsoft encountered a quality issue that necessitated the update to go through additional testing and development before it is released. Microsoft is committed to only releasing high quality updates that fix the issues in question, and therefore we feel it is in the best interest of our customers to not release this update until it undergoes further testing," a Microsoft spokesman explained.

Other than saying it planned to release a solitary fix in last week's advanced bulletin, Microsoft is yet to disclose any details of the security bug other than to describe it as "critical". Redmond defines critical security vulns as those which might be exploited remotely and without any interaction by end users. Last month, Microsoft issued six security patches. Among the three critical patches was one to defend against a Plug and Play vulnerability which was rapidly seized upon by virus writers to create prolific Zotob and other worms, which caused pandemonium in unpatched Windows 2000 shops last month.

Microsoft said that although it won't be issuing any new security patches on Tuesday it will still issue updates to its malicious software removal tool and a number of software updates to software tools unrelated to security issues. Critics of Microsoft will doubtless use the incident to make unfavourable comparisons between the relative reliability of software fixes from Redmond and open source developers. The release of a broken fix would have drawn even sharper criticism, of course. Whatever Microsoft did it would have got some stick but it can take comfort from support from segments of the security community.

"This is a wise decision by Microsoft. If there is any indication in the testing process that the patch is broken, it is in the best interest of businesses to pull the patch. Microsoft has to run a strict testing process for all its patches to ensure that its patches do not adversely affect systems," said Alan Bentley, UK managing director of patch management firm PatchLink. ®

Protecting users from Firesheep and other Sidejacking attacks with SSL

More from The Register

next story
'Kim Kardashian snaps naked selfies with a BLACKBERRY'. *Twitterati gasps*
More alleged private, nude celeb pics appear online
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
UK.gov lobs another fistful of change at SME infosec nightmares
Senior Lib Dem in 'trying to be relevant' shocker. It's only taxpayers' money, after all
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
TOR users become FBI's No.1 hacking target after legal power grab
Be afeared, me hearties, these scoundrels be spying our signals
Snowden, Dotcom, throw bombs into NZ election campaign
Claim of tapped undersea cable refuted by Kiwi PM as Kim claims extradition plot
Freenode IRC users told to change passwords after securo-breach
Miscreants probably got in, you guys know the drill by now
THREE QUARTERS of Android mobes open to web page spy bug
Metasploit module gobbles KitKat SOP slop
BitTorrent's peer-to-peer chat app Bleep goes live as public alpha
A good day for privacy as invisble.im also reveals its approach to untraceable chats
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
The next step in data security
With recent increased privacy concerns and computers becoming more powerful, the chance of hackers being able to crack smaller-sized RSA keys increases.