ARN

Valentine's Day Patch Tuesday: Microsoft to issue 9 patches, 4 critical

Microsoft Thursday said that the second Patch Tuesday of 2012 will see nine security bulletins, four of which were deemed critical.

Three of the four critical bulletins address vulnerabilities in Windows, one of which also targets an Internet Explorer flaw that Wolfgang Kandek, CTO of Qualys, says should be treated with the "highest priority." This is because browser-based vulnerabilities have been exposed more quickly of late than those for legacy software, Kandek says.

The fourth critical bulletin targets the .NET framework and Silverlight. As for the remaining bulletins, all five are rated "important." Four address vulnerabilities in Windows while another resolves an issue with Office and Server Software.

With the release, Microsoft will exceed the seven bulletins issued last month, as well as nearly tripling the number of vulnerabilities addressed, from eight in January to 21 this month.

RELATED: Microsoft patch blows 'perfect game' but sends important message

However, when the trends of the past few years are taken into account, the second Patch Tuesday of 2012 is a sign of continued progress for Microsoft security. Paul Henry, security and forensic analyst at Lumension, called this Patch Tuesday a "pretty sweet Valentine's day" for the IT professionals responsible for implementing the bulletins, especially when compared to the last two years. Microsoft sent 12 patches and addressed 22 vulnerabilities in February 2011, a year after issuing 13 bulletins that addressed 26 vulnerabilities.

Especially coming off a similarly light January Patch Tuesday, in which seven bulletins were issued but just eight vulnerabilities were addressed, Henry says there are signs of optimism for Microsoft security.

"We've had two fairly light patching periods in a row, with just seven from Microsoft last month," Henry says. "Clearly, the company's renewed focus is paying off."

Tuesday's upcoming patch will bring the total number of security bulletins in 2012 to 16. In comparison, Microsoft had issued 14 combined patches in the first two months of 2011, following a light, two-patch month in January 2011.

Despite the slightly higher total in overall bulletins compared to the same time last year, Henry has said security improvements in updated versions of Microsoft products have been evident in the continued decline in security patches. In 2011, Microsoft issued 100 patches, down from 106 the year prior. The company also saw its lowest level of bulletins rated critical in 2011, at 32, since it began issuing them monthly in 2004.

Colin Neagle covers Microsoft security and network management for Network World. Keep up with his blog: Rated Critical, follow him on Twitter: @ntwrkwrldneagle.

Read more about software in Network World's Software section.

Nominations for the 2012 ARN IT Industry Awards open on Tuesday, June 12.

More about: Lumension, Microsoft, Qualys
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the ARN comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: internet explorer, Microsoft, Microsoft Patch Tuesday, operating systems, Patch Tuesday, qualys, security, software, Windows, Windows security
ARN Directory | Distributors relevant to this article
ASI Solutions , Bluechip Infotech , Compucon Computers , Dicker Data , Express Data , Express Online , ICT Distribution , Impact Systems Technology , Leader Computers , NewLease , Synnex Australia , Topstar Computer International , XiT Distribution , Xpress I.T. , COMPUTERLINKS
rhs_login_lockGet exclusive access to ARN's news, research and invitation only events.
ARN Distributor Directory
ARN Vendor Directory

iAsset is a channel management ecosystem that automates all major aspects of the entire sales,marketing and service process, including data tracking, integrated learning, knowledge management and product lifecycle management.