It’s A Record Patchapalooza Tuesday!

Does Microsoft Windows suck? Um, why do you ask?

Microsoft drops record 14 bulletins in largest-ever Patch Tuesday

It’s a very busy Patch Tuesday for Windows users: 14 bulletins covering 34 serious security vulnerabilities in Internet Explorer, Microsoft Windows, Microsoft Office, Silverlight, Microsoft XML Core Services and Server Message Block.

As previously reported, eight of the bulletins are rated “critical” because of the risk of remote code execution attacks. The other six are rated “important.”

The company also released a security advisory to warn of a new elevation of privilege issue in the Windows Service Isolation feature.

Windows users are urged to pay special attention to these four bulletins:

MS10-052 resolves a privately reported vulnerability in Microsoft’s MPEG Layer-3 audio codecs. The vulnerability could allow remote code execution if a user opens a specially crafted media file or receives specially crafted streaming content from a Web site. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged on user.

MS10-055 resolves a privately reported vulnerability in the Cinepak codec that could allow remote code execution if a user opens a specially crafted media file, or receives specially crafted streaming content from a Web. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged on user.

MS10-056 resolves four privately reported vulnerabilities in Microsoft Office. The most severe vulnerabilities could allow remote code execution if a user opens or previews a specially crafted RTF e-mail message. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Windows Vista and Windows 7 are less exploitable due to additional heap mitigation mechanisms in those operating systems.

MS10-060 resolves two privately reported vulnerabilities, both of which could allow remote code execution, in Microsoft .NET Framework and Microsoft Silverlight.

As Computerworld’s Gregg Keizer points out, the August update was the biggest ever by number of security bulletins, and equaled the single-month record for individual patches.

See also:
Microsoft Security Bulletin Summary for August 2010
MS10-052
MS10-055
MS10-056
MS10-060
Windows Update Home
Record Patch Tuesday yields critical Windows, IE fixes
Record Patch Tuesday: Where to Begin
It’s Microsoft Patch Tuesday: August 2010
Microsoft: Big Patch Tuesday for IT Administrators
Microsoft releases record number of security patches
Microsoft issues patches for a record 35 fresh security holes
Microsoft Issues Biggest Security Patch Yet

What the hell is Bill Gates selling anyway, a computer operating system or Swiss cheese?

/you’d better get busy downloading, this one takes a while, sucks if you have dial up

Advertisements

Okay Kids, It’s Tuesday, Remember What We Do On Tuesdays?

Why, we patch Windows on Tuesdays!

Microsoft Issues Four Patches, Fixes Critical Help Center Flaw

Microsoft (NSDQ:MSFT) released a mild bulletin for its July Patch Tuesday, repairing a total of five vulnerabilities with four security updates in Windows and Office, including a critical Help and Support Center flaw already exploited in the wild.

Of the four patches Microsoft released, three are considered critical, indicating that they can enable hackers to launch malicious attacks via remote code execution. The three critical flaws occur in both Microsoft Windows and Office, which included flaws in the Microsoft Help and Support Center, ActiveX and Canonical Display Driver. The fourth patch, ranked with the slightly less severe rating of “important,” occurs in Microsoft Outlook.

Hands down, security experts recommend that users apply a patch repairing a critical Help and Support Center flaw in Windows XP and supported editions of Windows Server 2003, which is currently being exploited in active attacks.

See also:
Microsoft security updates for July 2010
It’s Microsoft Patch Tuesday: July 2010
Microsoft Patch Tuesday for July 2010: four bulletins
Microsoft Issues Four Security Bulletins
Microsoft patches critical bugs in Windows, Office
Microsoft Patches Critical Security Holes, Ends Windows XP SP2 Support
One final patch for Windows XP Service Pack 2 before it reaches end-of-life
Microsoft Patches Windows, Office Bugs

You all know the drill for fixing this magnificent Bill Gates software.

/so, load ’em down, patch ’em up, patch ’em up, shut ’em down, boot ’em up, ride ’em on, Windows!