Feeds

MS preps 5 Windows critical fixes for busy Patch Tuesday

25 fixes overall

Boost IT visibility and business value

Microsoft has lined up 11 patches that collectively address 25 security vulnerabilities as part of its April Patch Tuesday security update.

Five of the scheduled patches fix critical flaws, all involving Windows vulnerabilities. All supported versions of Windows are addressed by this much heavier than usual update batch. "Important" patches for Microsoft Office and Microsoft Exchange are also being loaded up for delivery next week.

Microsoft is due to fix two open zero-day vulnerabilities, notes Wolfgang Kandek, CTO at vulnerability scanning services firm Qualys. These are the F1 attack through Internet Explorer and the SMBv2 Denial of Service vulnerability, which only affects Windows 7 and Windows Server 2008.

A run-down of the fixes can be found in Microsoft's pre-bulletin here.

Critical updates from Adobe are also due next Tuesday, fixing well-publicised flaws in the company's Reader PDF client software.

The Adobe updates are due as part of a quarterly patch batch. More and more vendors have begun updating regular patching cycles, either monthly or quarterly, to help sysadmins predict and manage patching workloads. In the latest move in this industry-wide trend, Oracle announced on Thursday that it had moved Solaris updates onto its pre-existing quarterly security patch release schedule.

Around a third (16 out of 47) of the vulnerabilities Oracle plans to address next Tuesday involve Sun Solaris. Eight might be remotely exploitable without authentication - the most serious category. Other patches fix flaws in Oracle's database products, collaboration suite and e-commerce software, as explained in a bulletin here. ®

5 things you didn’t know about cloud backup

More from The Register

next story
Munich considers dumping Linux for ... GULP ... Windows!
Give a penguinista a hug, the Outlook's not good for open source's poster child
The Return of BSOD: Does ANYONE trust Microsoft patches?
Sysadmins, you're either fighting fires or seen as incompetents now
Intel's Raspberry Pi rival Galileo can now run Windows
Behold the Internet of Things. Wintel Things
Microsoft cries UNINSTALL in the wake of Blue Screens of Death™
Cache crash causes contained choloric calamity
Eat up Martha! Microsoft slings handwriting recog into OneNote on Android
Freehand input on non-Windows kit for the first time
Linux kernel devs made to finger their dongles before contributing code
Two-factor auth enabled for Kernel.org repositories
Time to move away from Windows 7 ... whoa, whoa, who said anything about Windows 8?
Start migrating now to avoid another XPocalypse – Gartner
prev story

Whitepapers

5 things you didn’t know about cloud backup
IT departments are embracing cloud backup, but there’s a lot you need to know before choosing a service provider. Learn all the critical things you need to know.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.
Rethinking backup and recovery in the modern data center
Combining intelligence, operational analytics, and automation to enable efficient, data-driven IT organizations using the HP ABR approach.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.