Feeds

MS pulls upcoming Windows security patch

Quality of mercy

SANS - Survey on application security programs

Microsoft has pulled plans to release a critical Windows security patch on Tuesday citing quality concerns as the reason behind the late withdrawal. Last Thursday Microsoft announced its intent to release a solitary patch in September as part of its monthly patch cycle but by Friday afternoon the software giant had second thoughts prompting it to pull the planned release.

"Late in the testing process, Microsoft encountered a quality issue that necessitated the update to go through additional testing and development before it is released. Microsoft is committed to only releasing high quality updates that fix the issues in question, and therefore we feel it is in the best interest of our customers to not release this update until it undergoes further testing," a Microsoft spokesman explained.

Other than saying it planned to release a solitary fix in last week's advanced bulletin, Microsoft is yet to disclose any details of the security bug other than to describe it as "critical". Redmond defines critical security vulns as those which might be exploited remotely and without any interaction by end users. Last month, Microsoft issued six security patches. Among the three critical patches was one to defend against a Plug and Play vulnerability which was rapidly seized upon by virus writers to create prolific Zotob and other worms, which caused pandemonium in unpatched Windows 2000 shops last month.

Microsoft said that although it won't be issuing any new security patches on Tuesday it will still issue updates to its malicious software removal tool and a number of software updates to software tools unrelated to security issues. Critics of Microsoft will doubtless use the incident to make unfavourable comparisons between the relative reliability of software fixes from Redmond and open source developers. The release of a broken fix would have drawn even sharper criticism, of course. Whatever Microsoft did it would have got some stick but it can take comfort from support from segments of the security community.

"This is a wise decision by Microsoft. If there is any indication in the testing process that the patch is broken, it is in the best interest of businesses to pull the patch. Microsoft has to run a strict testing process for all its patches to ensure that its patches do not adversely affect systems," said Alan Bentley, UK managing director of patch management firm PatchLink. ®

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Putin tells Snowden: Russia conducts no US-style mass surveillance
Gov't is too broke for that, Russian prez says
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
Mounties always get their man: Heartbleed 'hacker', 19, CUFFED
Canadian teen accused of raiding tax computers using OpenSSL bug
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Arts and crafts store Michaels says 3 million credit cards exposed in breach
Meanwhile, Target investigators prepare for long process in nabbing hackers
prev story

Whitepapers

SANS - Survey on application security programs
In this whitepaper learn about the state of application security programs and practices of 488 surveyed respondents, and discover how mature and effective these programs are.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.