Feeds

Record Patch Tuesday with 17-bulletin bumper crop

Strap in: it's likely to be a bumpy ride

The Essential Guide to IT Transformation

Microsoft is lining up a record equaling 17 security bulletins, nine rated critical and eight classified as important, as part of the April edition of its monthly Patch Tuesday updates.

The 12 April security update batch will collectively address 64 security vulnerabilities. Bugs in Microsoft Windows, Microsoft Office, Internet Explorer, Visual Studio, and .NET Framework will all be patched.

Upcoming features will include a critical SMB Browser bug that affects all versions of Windows. Security vulnerability scanning firm Qualys warns that all supported versions of Office and Windows will need updating, a task that is likely to result in plenty of overtime for sysadmins.

"This is a huge update and system administrators should plan for deployment as all Windows systems including Server 2008 and Windows 7 are affected by critical bulletins," said Amol Sarwate, manager of the Vulnerability Research Lab at Qualys. "Frequently used office applications like Excel 2003 through 2010 and PowerPoint 2002 through 2010 are also affected."

Redmond also released 17 bulletins in December 2010 but these addressed a total of 40 flaws, and only two of the end-of-year-patch were deemed critical. The April edition is therefore a bigger deal than the December Patch batch and far in excess of the standard fare for Black Tuesday, which probably approximates at three to four bulletins a month.

Microsoft's heads-up for the upcoming carnage – we hope we're wrong on that but you can't help but worry with so many moving parts flying together at one time – can be found here. ®

Build a business case: developing custom apps

More from The Register

next story
14 antivirus apps found to have security problems
Vendors just don't care, says researcher, after finding basic boo-boos in security software
'Things' on the Internet-of-things have 25 vulnerabilities apiece
Leaking sprinklers, overheated thermostats and picked locks all online
iWallet: No BONKING PLEASE, we're Apple
BLE-ding iPhones, not NFC bonkers, will drive trend - marketeers
Only '3% of web servers in top corps' fully fixed after Heartbleed snafu
Just slapping a patched OpenSSL on a machine ain't going to cut it, we're told
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Israel's Iron Dome missile tech stolen by Chinese hackers
Corporate raiders Comment Crew fingered for attacks
Tor attack nodes RIPPED MASKS off users for 6 MONTHS
Traffic confirmation attack bared users' privates - but to whom?
Multipath TCP speeds up the internet so much that security breaks
Black Hat research says proposed protocol will bork network probes, flummox firewalls
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
The Essential Guide to IT Transformation
ServiceNow discusses three IT transformations that can help CIO's automate IT services to transform IT and the enterprise.
Maximize storage efficiency across the enterprise
The HP StoreOnce backup solution offers highly flexible, centrally managed, and highly efficient data protection for any enterprise.