Site Archives Patch Tuesday

March Patch Tuesday

Posted on March 10th, 2009

Microsoft has announced three new patches for its monthly release cycle.  One patch is rated critical, and affects both server and client operating systems.  This patch covers a remote code execution vulnerability, and should be patched as soon as possible. The other two patches are rated important, and only affect servers.  These vulnerabilities could allow spoofing, but not remote code execution.

February Patch Tuesday

Posted on February 10th, 2009

Microsoft has released four patches resolving two Critical and two Important vulnerabilities in various Microsoft products.

January Patch Tuesday

Posted on January 13th, 2009

Microsoft has announced a patch for a critical vulnerability affecting several versions of Windows for both servers and workstations. The vulnerability could allow a remote attacker to access a system with full privileges.

December Patch Tuesday

Posted on December 10th, 2008

Microsoft has released 8 new patches resolving 6 critical and 2 important vulnerabilities found in its various products.  The vulnerability for the Visual Basic 6.0 ActiveX Control has publicly available exploit code, so it should be patched as soon as possible. The products with critical severity vulnerabilities include:

  • GDI
  • Windows Search
  • Internet Explorer
  • Visual Basic 6.0 Runtime Extended Files (ActiveX Controls)
  • Microsoft Office Word
  • Microsoft Office Excel

Patch Tuesday

Posted on November 13th, 2008

Microsoft’s Patch Tuesday has arrived, and there are two new security patches available.  And although only a couple of patches were released, patching this month is just as important as ever.  The first patch deals with a critical flaw in the XML Core services, which are called by Internet Explorer.  This vulnerability could allow remote code execution.  The second patch deals with the Server Message Block (SMB) protocol, used for file sharing in Windows.  This patch is rated “important” by Microsoft, and could also result in remote code execution.  Both patches are listed as “exploitable” by Microsoft.  The patches are more critical on client workstations than servers, since they affect client programs such as web browsers.  Gladiator recommends you install these patches during your standard release cycle.

Patch Tuesday

Posted on October 14th, 2008

Today is Patch Tuesday, Microsoft’s monthly patch release day.  There were 11 new advisories released, with 4 of them critical, 6 important and 1 moderate.  The critical patches deal with Active Directory, Internet Explorer, Host Integration Server and Microsoft Excel.  These should be applied as soon as possible.   Remember to test them on a subset of your servers first to make sure they’re compatible with all of the software you currently run.