Microsoft prepares monster security update for next week

Microsoft prepares monster security update for next week

Will patch near-record 57 bugs in IE, Windows, Office and Exchange Server

Microsoft will issue 12 security updates next week, including two for Internet Explorer (IE), that will patch a near-record 57 vulnerabilities in the browser, Windows, Office and the enterprise-critical Exchange Server email software.

"These are some serious numbers," said Andrew Storms, director of security operations at nCircle, referring to the 57 bugs Microsoft plans to quash February 12.

And they're nearly a record, coming close to the all-time Patch Tuesday tally of 64 flaws, all patched with fixes in April 2011.

Five of the 12 updates will be pegged as "critical," Microsoft's highest threat rating, while the remainder will be labeled "important," the next step below critical.

Two of the five critical updates will address vulnerabilities in Windows XP Service Pack 3 (SP3) and Windows Vista. Among the important updates, five will affect Windows 7, four Windows 8, and three each for XP SP3 and Windows RT. The latter is the limited-functionality edition designed for tablets, and the one that powers Microsoft's own Surface RT tablet.

But what caught Storms' eye were the two separate updates for IE, both tagged as critical, that will patch IE6, IE7, IE8, IE9 and the latest browser, IE10.

"This is the first time I've seen them do this," said Storms of the one-two punch. "Unless there's been an 'out-of-band' update for IE, they've never released more than one update [for the browser] in a month."

Storms struggled to come up with ideas why Microsoft split what could have been one, albeit larger, update. "Why not just a cumulative update for IE?" he asked. "I certainly expect to see an interesting blog post next week with some long, convoluted explanation."

The most likely place where Microsoft would offer insight into why it crafted two IE updates is its Security Research & Defense blog, which regularly posts entries about complex or unusual updates from that month's Patch Tuesday.

The IE double-whammy could help enterprises manage patching next week. Or it could hurt them. "I can see it both ways," Storms said. "It may be more difficult because you have to test two updates. But it's also possible that they split them because one has more risk than the other." In the latter instance, enterprises will have more flexibility than usual, he said, and will be able to decide whether to apply only one, both or even neither.

"I can see that, but I still don't understand why they didn't put [all the patches] in one bulletin and wrap installation with some logic," said Storms. "[The only thing I can think of] is one bulletin is for the core of IE, and one is for something used by IE."

Another expert, Lumension security and forensic analyst Paul Henry, theorized that one of the IE updates might be related to recent vulnerabilities in Oracle's Java. Like other browsers, IE relies on an Oracle-provided plug-in to parse Java code.

"It's possible that this is related to the recent and ongoing Java issues," said Henry in an email Thursday. "Microsoft has a very close relationship with Oracle, so it wouldn't surprise me if these bulletins include Java patches."

Last week, Oracle accelerated the release of its regularly-scheduled security update -- initially slated to ship Feb. 19 -- citing "active exploitation 'in the wild' of one of the vulnerabilities affecting the Java Runtime Environment (JRE) in desktop browsers."

Oracle's early update came in the aftermath of several embarrassing "zero-day" vulnerabilities -- and the emergency patches necessary to quash those bugs -- as well as harsh criticism leveled by security professionals against Oracle for its handling of Java's problems.

Next week's fifth critical update affects Exchange Server 2007 and Exchange Server 2010, the second- and third-most-recent versions of Microsoft's email server software.

While details were absent -- Microsoft's advanced notification is always bare bones -- Storms said the simple fact that the update was judged critical and for Exchange should be enough to raise the antenna of IT pros. "They always concern me because Exchange is the critical business application," said Storms.

A patch failure or compatibility problem in an Exchange update could conceivably knock out a firm's email, with all the resulting chaos that creates among workers, and the conflict between them and IT.

Microsoft will release next week's 12 security updates on Feb. 12 at approximately 1 p.m. ET.

Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at @gkeizer, on Google+ or subscribe to Gregg's RSS feed. His email address is

See more by Gregg Keizer on

Read more about malware and vulnerabilities in Computerworld's Malware and Vulnerabilities Topic Center.

Follow Us

Join the ARN newsletter!

Error: Please check your email address.

Tags MicrosoftWindowssoftwareMalware and Vulnerabilitiesoperating systems



IN PICTURES: Nutanix's .NEXT channel event in Sydney (+20 photos)

IN PICTURES: Nutanix's .NEXT channel event in Sydney (+20 photos)

Nutanix recently held its customer and channel event, .NEXT, in Sydney. The event, held at the Sheraton on the Park saw attendance from more than 150 channel and technology partners and customers. It was the first in a series of events Nutanix is holding in A/NZ in August and September, the objective of which is to brief partners and customers on “what’s next” in the design and management of datacentre technology.

IN PICTURES: Nutanix's .NEXT channel event in Sydney (+20 photos)
IN PICTURES: EDGE 2015 sponsor debrief (+23 photos)

IN PICTURES: EDGE 2015 sponsor debrief (+23 photos)

Some of the sponsors of ARN's inaugural EDGE 2015 event got together at the ARN office for a debrief of the event. Over some drinks and cheese, these attendees got an update on some key statistics that arose from the EDGE event and discussed potential topics and improvements that can be made at next year's event.

IN PICTURES: EDGE 2015 sponsor debrief (+23 photos)
IN PICTURES: ARN Distributor Roundtable, Sydney, 26.08.15 (+26 photos)

IN PICTURES: ARN Distributor Roundtable, Sydney, 26.08.15 (+26 photos)

ARN hosted a distributor roundtable at Cafe Del Mar in Sydney, at which attendees and their partners discussed the changing role of the traditional IT distributor. They spoke about the challenges of digital disruption, the blurring lines of the channel in the age of digital transformation, and examined the ever-evolving business models. This roundtable was sponsored by Distribution Central, Exclusive Networks, Rhipe, and Hemisphere Technologies. Photos by ARN Editorial Director, Mike Gee.

IN PICTURES: ARN Distributor Roundtable, Sydney, 26.08.15 (+26 photos) is a channel management ecosystem that automates all major aspects of the entire sales, marketing and service process, including data tracking, integrated learning, knowledge management and product lifecycle management.

Show Comments