Risk
10/7/2010
10:42 PM
George V. Hulme
George V. Hulme
Commentary
50%
50%

Record Microsoft Patch Tuesday Ahead

Administrators, get your rest this weekend. According to Microsoft's advanced warning, next Tuesday is going to be a record-setter when it comes to software vulnerability updates.

Administrators, get your rest this weekend. According to Microsoft's advanced warning, next Tuesday is going to be a record-setter when it comes to software vulnerability updates.According to the software maker, there will be a total of 49 vulnerabilities covered in 16 separate security bulletins next week. Microsoft ranked 4 of those bulletins as "critical" (its most severe rating), 10 as important, and 2 as moderate.

The flaws will affect versions of Windows, Internet Explorer, Office, and .NET Framework. Groove Server and Microsoft SharePoint will also be updated.

Nine of the bulletins address flaws that could be remotely exploited by attackers.

There is reasoning behind the madness of such a large vulnerability dump. Many companies, such as those involved in retail, eCommerce, and financial services, lock down their infrastructures as the holiday shopping season swings into full steam and the year itself winds down.

While it's not much solace now, it does mean November and December shouldn't be so patch abundant.

For more information, visit Microsoft's advanced notification site.

As always, Microsoft will host a webcast for anyone who has questions, the Wednesday immediately following Patch Tuesday.

For my security and technology observations throughout the day, consider following me on Twitter.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3653
Published: 2015-07-06
Cross-site scripting (XSS) vulnerability in the template preview function in Foreman before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted provisioning template.

CVE-2014-9737
Published: 2015-07-06
Open redirect vulnerability in the Language Switcher Dropdown module 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a block.

CVE-2014-9738
Published: 2015-07-06
Multiple cross-site scripting (XSS) vulnerabilities in the Tournament module 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via an (1) account username, a (2) node title, or a (3) team entity title.

CVE-2014-9739
Published: 2015-07-06
Cross-site scripting (XSS) vulnerability in the Node Field module 7.x-2.x before 7.x-2.45 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors involving internal fields.

CVE-2014-9740
Published: 2015-07-06
Cross-site scripting (XSS) vulnerability in the Rules Link module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer rules links" permission to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in the (1) question and (2...

Dark Reading Radio
Archived Dark Reading Radio
Marc Spitler, co-author of the Verizon DBIR will share some of the lesser-known but most intriguing tidbits from the massive report