Six Patches Coming on Patch Tuesday

By Ed Oswald | Published December 7, 2006, 3:45 PM

Microsoft will issue six security patches next Tuesday, of which at least two will have a rating of critical. Missing from this list is a patch for a recently discovered zero-day flaw in Word: no updates are scheduled for the Office suite.

All of the patches except one will fix various issues for the Windows operating system, with one of those being critical. The sixth will be a critical patch for users of Microsoft's Visual Studio programming application.

While Microsoft never discloses the nature of the patches in order to protect users, sometimes past disclosures of vulnerabilities can give clues to the company's moves. For example, the Visual Studio flaw may deal with an exploit first disclosed in early November.

That vulnerability apparently put users at a possible risk for remote code execution, say experts.

Left unpatched is a zero-day exploit for Word 2003 and earlier versions. Earlier this week, the US-CERT team from the Dept. of Homeland Security warned that a previous patch seemed to be ineffective against a "malformed string vulnerability" within those applications.

Microsoft said that it was working on correcting the new vulnerability, but apparently the new exploit had been disclosed late enough that the company was not able to issue a patch in time for next Tuesday. It would not be out of the ordinary, however, for the company to release an out-of-cycle patch.

In addition to the security update, Microsoft also plans to issue an updated version of the Microsoft Windows Malicious Software Removal Tool.

Besides the security updates, Patch Tuesday will be quite busy on the non-security patch front. Four high-priority updates will be released through Windows Update, with 10 coming through Microsoft Update, the company said in its monthly advisory.

Comments

View comments by with a score of at least

Why is this news?

Score: 0

|

If there were no patches needed, THAT would be news!

Score: 0

|

no kidding

Score: 0

|

What else is new if it's from microsoft.

Score: 0

|

ZOIKS AGAIN!

have fun wondering if your safe...

Score: 0

|

Zoiks again, troll.

I use Windows, come get me smart guy.

Score: 0

|

Do Microsoft patches indicate that some one in the company is working...or that someone is NOT working? Hmmmmm.

Score: 0

|

Hopefully...someday...they release the patch for the high processor usage of svchost that many people have been suffering with lately.

Score: 0

|

As of 12/7/2005 there are 62 HotFixes/Updates -- not including the hog IE-7.x or MP11... How about a SP3? No one in their right mind is going to move to Vista until 2008 or SP10.

Score: 0

|

svchost is only a proxy. It doesn't consume that much on its own. The processes it spawns are what typically eat the CPU and RAM.

Score: 0

|

http://support.microsoft...px?scid=kb;en-us;914810
The Automatic Updates service may stop responding

http://support.microsoft...px?scid=kb;en-us;916089
FIX: When you run Windows Update to scan for updates that use Windows Installer, including Office updates, CPU utilization may reach 100 percent for prolonged periods

Score: 0

|

Thanx...I know it can be resolved by disabling Microsoft Update and just using Windows Update.

Score: 0

|

How do you do that?

Score: 0

|

This is for "All Windows XP". You can narrow it down, though, to Home, Pro or whatever you like, then sort by popularity or release date.

http://www.microsoft.com...-4317-A1A9-0C56CD979D05

However, I prefer Autopatcher here:

http://www.autopatcher.com/downloads/

Score: 0

|

Will Firefox beat IE9 to Direct2D rendering?

Just days after Microsoft executives gave conference attendees a peek at a new rendering technology, a Mozilla contributor revealed he's working on the same thing.

AOL's decision to rebrand as Aol. takes a bad brand and makes it worse

The idea behind the social Web is to crowd source before bringing out something new. But not at AOL, which new logo debuted with a cry of "fail!" across the blogosphere and Twittersphere today.

Microsoft's Bob Muglia and Ray Ozzie on Silverlight vs. standards

Bob Muglia: "We're trying to provide people with an environment that has capabilities that you just simply can't do today in the standards-based world."

Uh-oh, netbooks -- not Windows 7 -- will lift 2009 PC sales

Santa may bring a lump of coal to the Windows PC industry this holiday season. Netbook sales will sap PC margins, while weak Windows 7 PC sales could further drive down average selling prices.

Kindle 2 update adds battery life, native PDF reader

Amazon has pushed out an update to the Kindle 2 e-reader that lengthens battery life and adds a native PDF viewer.

Safari on iPhone gets competition from a $1 browser app

Apple likes to say it gives iPhone users a full browsing experience, but a new competitor tries to incorporate more desktop browser features.

Action Replay maker sues Microsoft for Xbox 360 'predatory technological barriers'

Third-party video game accessory maker Datel has filed an antitrust lawsuit against Microsoft over the Xbox 360's recent Dashboard update.

Where there's smoke: Apple warranty stance raises troubling questions

Carmi Levy | Wide Angle Zoom: Smoking can be dangerous not only for your lungs, it appears, but for your Apple hardware warranty.

Microsoft's .NET Micro Framework is now free and open source

The latest version of Microsoft's .NET Micro framework is now in the hands of the FOSS community.

Google's value proposition for Chrome OS: Should we feel insulted?

For a search engine that has direct access to all the world's online history, it appears to have taught Google nothing about selling a machine.

E-book readers will be in short supply this holiday season

E-readers are hot this year, and a lot of compelling new products have been released, but are there enough electrophoretic displays to go around?