Personal tools
About this blog
This is where I maintain running notes of my thoughts

Syndicate my Blog

 Subscribe in a reader


Number of visitors since 27 March 2006
Site Meter
Add to Technorati Favorites

 
Document Actions

Microsoft Patch Tuesday for November

by Mukul Dharwadkar posted at 2006-11-14 17:20 last modified 2006-11-14 17:20

MeetMeNow 14-day free trial; easy web meetings VistaPrint.com

Digg!

Microsoft has released six (6) updates for Windows for November. Five of these updates are rated critical and the general recommendation is to apply the patches immediately as each one of those involve remote code execution. One update is rated important and it affects Client Services for NetWare (CSNW). If you don't have Netware in your environment you can safely ignore this update. The impact is again limited by the fact that the CSNW is not installed by default on any of the Windows operating systems.

Microsoft has fixed totally 12 vulnerabilities this month with five of those affecting Macromedia Flash Player from Adobe. I am not covering the patches here in detail, but will do so in a detailed article and will try to address each vulnerability in greater depth and details with my recommendations. In my last post on this subject, I had mentioned that I expected Microsoft to patch the recently disclosed vulnerability with Windows Server 2003 running Visual Studio 2005 that is described in Microsoft Security Advisory 927709. The same issue gained some traction in the technology media though some experts did expect Microsoft not to release a patch for it during this cycle as it had very less time to work on it.

I think that Microsoft should have spent more resources on this in getting a patch out for this vulnerability in this cycle as it involves remote code execution. Attackers would definitely try to take advantage of this vulnerability now that they know that the vulnerability exists and a patch isn't coming for at least another month. If there are attacks, then again there might be some third party security researcher / company who will come out with an "unofficial" patch which Microsoft will not support. At the end of the day, where should the customer turn to? Should he trust third party software and apply the patch hoping that nothing else will break or do nothing and hope that his infrastructure won't be attacked.

I don't know.


What to expect on Patch Tuesday for November... What to expect on Patch Tuesday for November...
Size 1624 - File type text/html
by Mukul Dharwadkar — last modified 2006-11-14 17:20
The URL to Trackback this entry is:
http://www.dharwadkar.com/weblog/patchtues_nov_rel/tbping
Add comment

You can add a comment by filling out the form below. Plain text formatting.

(Required)
(Required)

Listed on BlogShares
Recent entries
My experience with virtualization Mukul Dharwadkar 2008-06-30
Happy Father's day Mukul Dharwadkar 2008-06-16
Use the plain old notepad as your personal diary Mukul Dharwadkar 2008-05-07
Taxing time to file tax returns Mukul Dharwadkar 2008-02-29
Fedora 8 - Still not there yet Mukul Dharwadkar 2008-02-28
Recent comments
Re:Configuring Gmail POP on Lotus Notes Anonymous User 2008-08-22
Re:How to repair a broken Ubuntu Desktop installation Anonymous User 2008-08-20
Re:Configuring Gmail POP on Lotus Notes Beery 2008-07-24
Re:How to install IDLE on Fedora 7 Anonymous User 2008-07-17
Re:Google Docs does not measure up.... yet Mukul Dharwadkar 2008-07-09
Recent trackbacks
2006-11-07
2006-11-07
2006-11-07
2006-11-07
2006-11-07
« August 2008 »
Su Mo Tu We Th Fr Sa
          1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
31            
 

This site is:

Powered by Plone, the Open Source Content Management System