Feeds

MS pulls upcoming Windows security patch

Quality of mercy

The essential guide to IT transformation

Microsoft has pulled plans to release a critical Windows security patch on Tuesday citing quality concerns as the reason behind the late withdrawal. Last Thursday Microsoft announced its intent to release a solitary patch in September as part of its monthly patch cycle but by Friday afternoon the software giant had second thoughts prompting it to pull the planned release.

"Late in the testing process, Microsoft encountered a quality issue that necessitated the update to go through additional testing and development before it is released. Microsoft is committed to only releasing high quality updates that fix the issues in question, and therefore we feel it is in the best interest of our customers to not release this update until it undergoes further testing," a Microsoft spokesman explained.

Other than saying it planned to release a solitary fix in last week's advanced bulletin, Microsoft is yet to disclose any details of the security bug other than to describe it as "critical". Redmond defines critical security vulns as those which might be exploited remotely and without any interaction by end users. Last month, Microsoft issued six security patches. Among the three critical patches was one to defend against a Plug and Play vulnerability which was rapidly seized upon by virus writers to create prolific Zotob and other worms, which caused pandemonium in unpatched Windows 2000 shops last month.

Microsoft said that although it won't be issuing any new security patches on Tuesday it will still issue updates to its malicious software removal tool and a number of software updates to software tools unrelated to security issues. Critics of Microsoft will doubtless use the incident to make unfavourable comparisons between the relative reliability of software fixes from Redmond and open source developers. The release of a broken fix would have drawn even sharper criticism, of course. Whatever Microsoft did it would have got some stick but it can take comfort from support from segments of the security community.

"This is a wise decision by Microsoft. If there is any indication in the testing process that the patch is broken, it is in the best interest of businesses to pull the patch. Microsoft has to run a strict testing process for all its patches to ensure that its patches do not adversely affect systems," said Alan Bentley, UK managing director of patch management firm PatchLink. ®

Next gen security for virtualised datacentres

More from The Register

next story
Snowden on NSA's MonsterMind TERROR: It may trigger cyberwar
Plus: Syria's internet going down? That was a US cock-up
Who needs hackers? 'Password1' opens a third of all biz doors
GPU-powered pen test yields more bad news about defences and passwords
e-Borders fiasco: Brits stung for £224m after US IT giant sues UK govt
Defeat to Raytheon branded 'catastrophic result'
Microsoft cries UNINSTALL in the wake of Blue Screens of Death™
Cache crash causes contained choloric calamity
Germany 'accidentally' snooped on John Kerry and Hillary Clinton
Dragnet surveillance picks up EVERYTHING, USA, m'kay?
Linux kernel devs made to finger their dongles before contributing code
Two-factor auth enabled for Kernel.org repositories
prev story

Whitepapers

5 things you didn’t know about cloud backup
IT departments are embracing cloud backup, but there’s a lot you need to know before choosing a service provider. Learn all the critical things you need to know.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.
Rethinking backup and recovery in the modern data center
Combining intelligence, operational analytics, and automation to enable efficient, data-driven IT organizations using the HP ABR approach.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.