Trade Resources Industry Views Corporate IT Departments Will Be Faced with a "Mega Patch" Tuesday From Microsoft Today

Corporate IT Departments Will Be Faced with a "Mega Patch" Tuesday From Microsoft Today

Corporate IT departments will be faced with a "mega patch" Tuesday from Microsoft today.

The patches to Microsoft's various Windows operating systems and essential applications will patch a number of flaws that are already being exploited "in the wild", according to Microsoft.

Further reading

Microsoft Patch Tuesday promises busy week for admins Patch Tuesday: a look behind the scenes

In total, some 33 vulnerabilities ought to be fixed by the 10 patches that Microsoft will be issuing. Eight are rated "important" and two "critical". Users will be required to reboot their machines.

The mega-patch will make good a remote code execution flaw affecting Internet Explorer versions 6, 7, 8, 9 and 10, running on all Windows operating systems except Windows XP.

The remaining patches ought to address remote code execution flaws in various versions of the Microsoft Office applications suite and Lync, Microsoft's communications suite, as well as vulnerabilities to spoofing and elevation of privilege known to exist in currently supported versions of Windows, from XP to the latest, Windows RT and Windows 8.

However, the Sophos Naked Security blog questions whether the latest set of patches will provide a definitive fix for CVE-2013-1347.

"This is a remote code execution flaw in Internet Explorer 8 that has already been exploited in the wild to disseminate malware, most notably via a hacked website belonging to the US Department of Labor," wrote Paul Ducklin.

He continued: "Microsoft has already published a temporary patch... in the form of a fix-it tool, and has announced that it would like to have a permanent patch available in time for the coming patch Tuesday."

Security specialists have also speculated over whether the latest batch of Microsoft patches will include a fix for a bug uncovered during the Pwn2Own hacking competition in March.

Source: http://www.computing.co.uk/ctg/news/2267731/microsoft-promising-mega-patch-tuesday#comment_form
Contribute Copyright Policy
Microsoft Promising 'Mega Patch' Tuesday