Feeds

MS preps 5 Windows critical fixes for busy Patch Tuesday

25 fixes overall

Secure remote control for conventional and virtual desktops

Microsoft has lined up 11 patches that collectively address 25 security vulnerabilities as part of its April Patch Tuesday security update.

Five of the scheduled patches fix critical flaws, all involving Windows vulnerabilities. All supported versions of Windows are addressed by this much heavier than usual update batch. "Important" patches for Microsoft Office and Microsoft Exchange are also being loaded up for delivery next week.

Microsoft is due to fix two open zero-day vulnerabilities, notes Wolfgang Kandek, CTO at vulnerability scanning services firm Qualys. These are the F1 attack through Internet Explorer and the SMBv2 Denial of Service vulnerability, which only affects Windows 7 and Windows Server 2008.

A run-down of the fixes can be found in Microsoft's pre-bulletin here.

Critical updates from Adobe are also due next Tuesday, fixing well-publicised flaws in the company's Reader PDF client software.

The Adobe updates are due as part of a quarterly patch batch. More and more vendors have begun updating regular patching cycles, either monthly or quarterly, to help sysadmins predict and manage patching workloads. In the latest move in this industry-wide trend, Oracle announced on Thursday that it had moved Solaris updates onto its pre-existing quarterly security patch release schedule.

Around a third (16 out of 47) of the vulnerabilities Oracle plans to address next Tuesday involve Sun Solaris. Eight might be remotely exploitable without authentication - the most serious category. Other patches fix flaws in Oracle's database products, collaboration suite and e-commerce software, as explained in a bulletin here. ®

Next gen security for virtualised datacentres

More from The Register

next story
The Return of BSOD: Does ANYONE trust Microsoft patches?
Sysadmins, you're either fighting fires or seen as incompetents now
Microsoft refuses to nip 'Windows 9' unzip lip slip
Look at the shiny Windows 8.1, why can't you people talk about 8.1, sobs an exec somewhere
Intel's Raspberry Pi rival Galileo can now run Windows
Behold the Internet of Things. Wintel Things
Linux Foundation says many Linux admins and engineers are certifiable
Floats exam program to help IT employers lock up talent
Microsoft cries UNINSTALL in the wake of Blue Screens of Death™
Cache crash causes contained choloric calamity
Eat up Martha! Microsoft slings handwriting recog into OneNote on Android
Freehand input on non-Windows kit for the first time
Linux kernel devs made to finger their dongles before contributing code
Two-factor auth enabled for Kernel.org repositories
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
7 Elements of Radically Simple OS Migration
Avoid the typical headaches of OS migration during your next project by learning about 7 elements of radically simple OS migration.
BYOD's dark side: Data protection
An endpoint data protection solution that adds value to the user and the organization so it can protect itself from data loss as well as leverage corporate data.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?