Feeds

MS preps 5 Windows critical fixes for busy Patch Tuesday

25 fixes overall

The essential guide to IT transformation

Microsoft has lined up 11 patches that collectively address 25 security vulnerabilities as part of its April Patch Tuesday security update.

Five of the scheduled patches fix critical flaws, all involving Windows vulnerabilities. All supported versions of Windows are addressed by this much heavier than usual update batch. "Important" patches for Microsoft Office and Microsoft Exchange are also being loaded up for delivery next week.

Microsoft is due to fix two open zero-day vulnerabilities, notes Wolfgang Kandek, CTO at vulnerability scanning services firm Qualys. These are the F1 attack through Internet Explorer and the SMBv2 Denial of Service vulnerability, which only affects Windows 7 and Windows Server 2008.

A run-down of the fixes can be found in Microsoft's pre-bulletin here.

Critical updates from Adobe are also due next Tuesday, fixing well-publicised flaws in the company's Reader PDF client software.

The Adobe updates are due as part of a quarterly patch batch. More and more vendors have begun updating regular patching cycles, either monthly or quarterly, to help sysadmins predict and manage patching workloads. In the latest move in this industry-wide trend, Oracle announced on Thursday that it had moved Solaris updates onto its pre-existing quarterly security patch release schedule.

Around a third (16 out of 47) of the vulnerabilities Oracle plans to address next Tuesday involve Sun Solaris. Eight might be remotely exploitable without authentication - the most serious category. Other patches fix flaws in Oracle's database products, collaboration suite and e-commerce software, as explained in a bulletin here. ®

5 things you didn’t know about cloud backup

More from The Register

next story
BBC: We're going to slip CODING into kids' TV
Pureed-carrot-in-ice cream C++ surprise
China: You, Microsoft. Office-Windows 'compatibility'. You have 20 days to explain
Told to cough up more details as antitrust probe goes deeper
Linux turns 23 and Linus Torvalds celebrates as only he can
No, not with swearing, but by controlling the release cycle
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
This is how I set about making a fortune with my own startup
Would you leave your well-paid job to chase your dream?
prev story

Whitepapers

Endpoint data privacy in the cloud is easier than you think
Innovations in encryption and storage resolve issues of data privacy and key requirements for companies to look for in a solution.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Advanced data protection for your virtualized environments
Find a natural fit for optimizing protection for the often resource-constrained data protection process found in virtual environments.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.