Email this article   Print article 


Microsoft Patch Tuesday Issues Updates, Takes A Do-Over

By Ken Presti
October 09, 2012    4:54 PM ET

Page 2 of 2

Remaining patches are listed as "important" and close vulnerabilities in SQL Server, Microsoft Works, Kerberos and SharePoint. Two of the bulletins address additional concerns such as HTML sanitization and a vulnerability in the Windows kernel that could enable elevation of privilege.

"Look at the products that are being patched and then prioritize based on what's running on your network," advised VMware's Miller. "If you're a heavy SQL user, you could easily be vulnerable to a cross-site scripting attack, so that might be one that you move to the front of the line."

According to Paul Henry, security and forensic analyst at Lumension, Microsoft appears to be making headway in its ongoing drive to enhance OS security. He ties this improvement to the company's Secure Coding efforts.

"If you look at the numbers, last year at this time we had well over 80 patches; this year to date, we are at 70. So, that's a nice drop overall," he said. "Critical issues plaguing their operating systems seem to have dropped off. I hope it's not just a skew in the numbers.

"Shortly after XP, Microsoft really started to drill down hard on security," he continued. "They went overboard in many respects with Vista, and it began to impact user experience. So, they backed up and regrouped with Windows 7, which is really Vista Two. So, it looks like they're getting their ducks in a row."

PUBLISHED OCT. 9, 2012

<< Previous | 1 | 2

To continue reading this article, please download the free CRN Tech News app for your iPad or Windows 8 device.
Related: Videos | Slide Shows | Comments

SHARE THIS ARTICLE

More Security

Recent Articles

Head-To-Head: Symantec Vs. McAfee In Endpoint Protection

McAfee and Symantec are archrivals with a firm grip on the North American security market. CRN pits both vendors' endpoint security products against each other and names a winner.

The 8 Steps Behind The Massive $45M Cyber Bank Heist

More than $45 million was stolen from banks in the U.S. and 19 other countries in a scheme that law enforcement is calling an international conspiracy to drain millions from bank accounts using stolen debit cards and PIN numbers. Here's how they did it.

Name Of The Game: Top 10 States For Identity Theft

A Federal Trade Commission report provides statistics on identity theft and fraud complaints in 2012. Learn which state has the dubious distinction of having the most victims.

  More Slide Shows




Related Videos
Loading...