Feeds

MS January patch update omits critical Word fix

Half measures

Top 5 reasons to deploy VMware with Tegile

Microsoft released four patches on Tuesday - half the number initially expected - that address a number of critical flaws in its Windows OS, Outlook and Office software.

None of the three is critical and one important security fix published by Microsoft addresses a trio of Word flaws, which have been left flapping since early December.

One of the patches Microsoft did release addresses a slew of vulnerabilities in Excel that create a means for hackers to load malware onto vulnerable systems (MS07-002).

Another critical patch (MS07-003) addresses flaws in Microsoft Outlook that carries a similar risk while the last of the trio aims to lance security bugs in Microsoft's implementation of Vector Markup Language in Windows ((MS07-004) that also carry the risk of remote code execution.

Redmond also released a fix for a less severe (important) bug in Microsoft Office 2003's Brazilian Portuguese grammar checker.

Security vendors reckon the need to test the Word patches more comprehensively is behind Redmond's decision to hold back these fixes.

"Microsoft held back on four anticipated patches prior to general release this month. Instead, Microsoft released half of what it promised - three sets of critical patches and one important patch, fixing nine security bugs. While this may come as a surprise to some IT administrators, Microsoft is taking a cautionary approach with its patch release to ensure minimal business impact and disruption to its customers," said Alan Bentley, managing director of patch management firm PatchLink.

"Testing patches is absolutely critical but an often overlooked element of patch management process. Microsoft did the right thing in holding back the four patches that most likely didn’t pass the QA(Quality Assurance) testing before releasing them to its large user base," he added.

Since exploits are available for the Outlook and VML flaws applying patches that address these security flaws ought to be the main priority for sys admins, PatchLink advises.

Microsoft's summary of its security patches can be found here and there's more information of the relative severity of the vulnerabilities, via the SANS Institute's Internet Storm Centre here. ®

Internet Security Threat Report 2014

More from The Register

next story
'Kim Kardashian snaps naked selfies with a BLACKBERRY'. *Twitterati gasps*
More alleged private, nude celeb pics appear online
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
UK.gov lobs another fistful of change at SME infosec nightmares
Senior Lib Dem in 'trying to be relevant' shocker. It's only taxpayers' money, after all
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
TOR users become FBI's No.1 hacking target after legal power grab
Be afeared, me hearties, these scoundrels be spying our signals
Snowden, Dotcom, throw bombs into NZ election campaign
Claim of tapped undersea cable refuted by Kiwi PM as Kim claims extradition plot
Freenode IRC users told to change passwords after securo-breach
Miscreants probably got in, you guys know the drill by now
THREE QUARTERS of Android mobes open to web page spy bug
Metasploit module gobbles KitKat SOP slop
BitTorrent's peer-to-peer chat app Bleep goes live as public alpha
A good day for privacy as invisble.im also reveals its approach to untraceable chats
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.