Feeds

Record Patch Tuesday with 17-bulletin bumper crop

Strap in: it's likely to be a bumpy ride

SANS - Survey on application security programs

Microsoft is lining up a record equaling 17 security bulletins, nine rated critical and eight classified as important, as part of the April edition of its monthly Patch Tuesday updates.

The 12 April security update batch will collectively address 64 security vulnerabilities. Bugs in Microsoft Windows, Microsoft Office, Internet Explorer, Visual Studio, and .NET Framework will all be patched.

Upcoming features will include a critical SMB Browser bug that affects all versions of Windows. Security vulnerability scanning firm Qualys warns that all supported versions of Office and Windows will need updating, a task that is likely to result in plenty of overtime for sysadmins.

"This is a huge update and system administrators should plan for deployment as all Windows systems including Server 2008 and Windows 7 are affected by critical bulletins," said Amol Sarwate, manager of the Vulnerability Research Lab at Qualys. "Frequently used office applications like Excel 2003 through 2010 and PowerPoint 2002 through 2010 are also affected."

Redmond also released 17 bulletins in December 2010 but these addressed a total of 40 flaws, and only two of the end-of-year-patch were deemed critical. The April edition is therefore a bigger deal than the December Patch batch and far in excess of the standard fare for Black Tuesday, which probably approximates at three to four bulletins a month.

Microsoft's heads-up for the upcoming carnage – we hope we're wrong on that but you can't help but worry with so many moving parts flying together at one time – can be found here. ®

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Putin tells Snowden: Russia conducts no US-style mass surveillance
Gov't is too broke for that, Russian prez says
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
Mounties always get their man: Heartbleed 'hacker', 19, CUFFED
Canadian teen accused of raiding tax computers using OpenSSL bug
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Arts and crafts store Michaels says 3 million credit cards exposed in breach
Meanwhile, Target investigators prepare for long process in nabbing hackers
Canadian taxman says hundreds pierced by Heartbleed SSL skewer
900 social insurance numbers nicked, says revenue watchman
prev story

Whitepapers

SANS - Survey on application security programs
In this whitepaper learn about the state of application security programs and practices of 488 surveyed respondents, and discover how mature and effective these programs are.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.