Feeds

MS pulls upcoming Windows security patch

Quality of mercy

Security for virtualized datacentres

Microsoft has pulled plans to release a critical Windows security patch on Tuesday citing quality concerns as the reason behind the late withdrawal. Last Thursday Microsoft announced its intent to release a solitary patch in September as part of its monthly patch cycle but by Friday afternoon the software giant had second thoughts prompting it to pull the planned release.

"Late in the testing process, Microsoft encountered a quality issue that necessitated the update to go through additional testing and development before it is released. Microsoft is committed to only releasing high quality updates that fix the issues in question, and therefore we feel it is in the best interest of our customers to not release this update until it undergoes further testing," a Microsoft spokesman explained.

Other than saying it planned to release a solitary fix in last week's advanced bulletin, Microsoft is yet to disclose any details of the security bug other than to describe it as "critical". Redmond defines critical security vulns as those which might be exploited remotely and without any interaction by end users. Last month, Microsoft issued six security patches. Among the three critical patches was one to defend against a Plug and Play vulnerability which was rapidly seized upon by virus writers to create prolific Zotob and other worms, which caused pandemonium in unpatched Windows 2000 shops last month.

Microsoft said that although it won't be issuing any new security patches on Tuesday it will still issue updates to its malicious software removal tool and a number of software updates to software tools unrelated to security issues. Critics of Microsoft will doubtless use the incident to make unfavourable comparisons between the relative reliability of software fixes from Redmond and open source developers. The release of a broken fix would have drawn even sharper criticism, of course. Whatever Microsoft did it would have got some stick but it can take comfort from support from segments of the security community.

"This is a wise decision by Microsoft. If there is any indication in the testing process that the patch is broken, it is in the best interest of businesses to pull the patch. Microsoft has to run a strict testing process for all its patches to ensure that its patches do not adversely affect systems," said Alan Bentley, UK managing director of patch management firm PatchLink. ®

Beginner's guide to SSL certificates

Whitepapers

Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.