Top Tech News

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
News & Product Reviews for Tech Leaders
Panasonic Toughbook® Mobile
Tablets & Laptops are rugged & reliable
with lower TCO & greater ROI

www.panasonic.com
Sunday, May 19th 
Introducing Simpana® 10 software
Home
Network Security
Microsoft/Windows
Linux/Open Source
Apple/Mac
Mobile Tech
World Wide Web
Tech Trends
Data Storage
Applications
Hardware
Unified Communications
Spam & Hackers
Chips & Processors
Cloud & Virtualization
Personal Tech
Press Releases
 
Free Newsletters
Top CIO News
 
Mobile Tech Today
 

Advertisement


Microsoft/Windows

Microsoft Patch Tuesday Shows Secure Coding Pays Off

Microsoft Patch Tuesday Shows Secure Coding Pays Off
December 12, 2012 10:18AM

Bookmark and Share
Security researcher Paul Henry said it was great to see Microsoft's Secure Coding Initiative paying off, reducing the number of vulnerabilities in its software, resulting in an easier time for IT at Patch Tuesday time. Over the year, Microsoft Patch Tuesday released 35 critical security bulletins, 46 important bulletins and two moderate bulletins.

Brocade delivers a comprehensive cloud-optimized networking portfolio of products and open-architecture solutions to simplify and accelerate the deployment of cloud computing and provide maximum deployment flexibility with plug-in scalability. Click here to learn more.

Microsoft Relevant Products/Services's last Patch Tuesday of 2012 rolled out seven patches. Five of them are rated critical and two are rated important. The good news is: none are under active attack.

With December's Patch Tuesday, Microsoft has rolled out 83 security bulletins in 2012. That's significantly down from the 100 security bulletins Redmond released in 2011. Microsoft released 117 security bulletins in 2010.

"Maybe even more important than the raw numbers is the more regular release rhythm that Microsoft set this year," said Wolfgang Kandek, CTO at Qualys. "We see this as a clear sign of a more mature process."

Prioritizing the Patches

Looking at December's patches, five of this month's bulletins are rated as critical. That means an attacker can use the vulnerabilities Microsoft is fixing to gain complete control over the victim's machine.

"Of the five, we think that MS12-079, a bulletin for Microsoft Word, is the most important. The attack can be accomplished through e-mail using a flaw in the Rich Text Format," Kandek told us. "An attacker can gain control of a computer Relevant Products/Services without end user interaction because Microsoft Outlook automatically displays the malicious text in the Preview Pane."

Kandek pointed to a potential work-around: manually configuring the preview pane in Outlook's Trust Center to use plain text only. The downside is you lose a significant amount of functionality by opting for this workaround.

Kandek put the Internet Explorer bulletin MS12-077 in a close second with regard to IT patching priorities. MS12-077 addresses vulnerabilities in IE 9 and 10, the newest versions of IE that run under Vista, Windows 7 and Windows 8.

"Here, an attacker would have to lure the attack target to browse to a malicious Web page," Kandek said. "This is a tad harder than sending the target a simple e-mail, another common attack method."

Secure Coding Initiative Pays Off

Paul Henry, a security and forensic analyst for Lumension, also pulled the camera back and took a wide view of 2012. With the multitude of third-party application patching needed this year from the likes of Adobe, Java and even Apple, he said, you likely didn't notice Microsoft put out 20 percent fewer patches in 2011.

Over the year, Microsoft Patch Tuesday released 35 critical bulletins, 46 important bulletins and two moderate bulletins. Henry said it was great to see Microsoft's Secure Coding Initiative paying off, reducing the number of vulnerabilities in its software Relevant Products/Services, resulting in an easier time for IT at Patch Tuesday time.

"A look back over the last couple of years proves interesting. In 2011, January had two bulletins, while February had 12. March then went back down to three, but April went up to 17. May had two and June went back up to 16," Henry said.

"In contrast, January of this year had seven patches, February had nine, then six in both March and April, and seven in both May and June. In fact, only one month -- September, at three -- was lower than six or higher than nine. The degree of consistency makes it easier for IT to plan out the time and effort they'll need to spend on Patch Tuesday each month."

Tell Us What You Think
Comment:

Name:

Norm:

Posted: 2012-12-13 @ 10:29am PT
@Shickadee: Mine went smoothly. You might want to try again, but also report the problem directly to Microsoft. Good luck.

Shickadee:

Posted: 2012-12-13 @ 10:26am PT
This December's update couldn't make it past the 7th of twelve updates. After waiting more than 1/2 a day for it to complete, I finally chanced it and restarted my computer. Thankfully it recovered okay. This is the 1st time this has happened, with all the Windows 7 updates. Has anyone else had this problem?

Advertisement



 Microsoft/Windows
1. Windows 8.1: No Cost, Big Pressure
2. Should Enterprises Skip Windows 8?
3. IDC: Windows Phone Now in 3rd Place
4. Windows Blue Officially 8.1 and Free
5. Uneasy Alliance for Microsoft, Google


advertisement


 Most Popular Articles
1. Best of Interop Award Winners Announced
2. HP Teams with Avaya To Take Contact Centers Virtual
3. Sony Vaio Fit Notebooks Aim for Sweet Spot
4. Salesforce Sees End to Legacy Portals with Its Communities
5. EMC Debuts ViPR Software-Defined Storage Platform


advertisement

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  What's in Store for Apple's iOS 7?
  Facebook Steadies, Year Post IPO Flop
  Batteries May Fuel Solar, Wind Growth
  Windows 8.1: No Cost, Big Pressure
  Google Glass Raises Privacy Concerns

 Technology Marketplace

BYOD & MDM
Build a business case for a BYOD program.
 
CRM Systems
Free Download: Understanding the Voice of the Customer
 
Cloud & Virtualization
Brocade technologies help enable the full benefits of virtualization.
Riverbed Stingray Traffic Manager on Amazon Web Services
 
Contact Centers
Unlock the potential in your people with Microsoft Dynamics
 
Customer Data
Free Download: Understanding the Voice of the Customer
 
Customer Service
Unlock the potential in your people with Microsoft Dynamics
 
Data Security
Simpana® 10 software: an exponential leap forward
 
Data Storage
Brocade makes it easier to deploy, manage, and scale networks.
 
Enterprise Software
Simpana® 10 software: an exponential leap forward
 
Hardware
Rugged and reliable Panasonic Toughbook® mobile computers.
 
Laptops & Tablets
Rugged and reliable Panasonic Toughbook® mobile computers.
 
Mobile Apps
Build great mobile apps that drive engagement.
 
Mobile Gadgets
Rugged and reliable Panasonic Toughbook® mobile computers.
 
Network Security
Brocade makes it easier to deploy, manage, and scale networks.
 
Mobile Enterprise Spotlight

What's in Store for Apple's iOS 7?
There's been talk recently that Apple's products are beginning to coast on their glorious past. So, with Apple's big Worldwide Developers Conference opening next month, speculation is heating up.

Google Glass Raises Congressional Privacy Concerns
The buzz around Google Glass continues, but it's not all good. Some in Congress have questions. "We are curious whether this new technology could infringe on the privacy of average Americans," their letter to Google says.

Windows Phone Now No. 3 in Market, BlackBerry No. 4
Has Microsoft Phone moved into a coveted though distant third place for smartphone platforms behind Google's Android and Apple's iOS? A new report says yes, while BlackBerry has slipped to No. 4.

Advertisement
Enterprise Software Spotlight

Should Enterprises Skip Over Windows 8?
Because of the interface changes and compatibility issues, most businesses will not adopt Windows 8 as their standard, but must be prepared to meet employee BYOD demand for it, Forrester Research says.

HP and SAP Team To Advance HANA Database Technology
The two tech leaders are working on a system that SAP says could fundamentally change the database market. HANA is SAP's technology that keeps data in-memory, for super fast processing.

Revlon Saving Millions with Microsoft Dynamics
The cosmetics giant is reporting millions of dollars in savings thanks to consolidating its enterprise resource planning by using Microsoft Dynamics ERP. Revlon CIO David Giambruno recently shared his story.

Advertisement
Enterprise Hardware Spotlight

U.S. Defense Department Gives iOS 6 Security OK
In a vote of confidence for Apple's iOS devices, the Defense Department has given the all-clear for employees to use iPads and iPhones for work. But only those running iOS 6, and only if issued by the government.

Cisco Surges After Profit Exceeds Analysts' Estimates
Networking equipment giant Cisco's net income jumped 14 percent in the latest quarter as revenue at all four of its divisions rose for the first time in a year and a half, as tech spending increases.

HP and SAP Team To Advance HANA Database Technology
The two tech leaders are working on a system that SAP says could fundamentally change the database market. HANA is SAP's technology that keeps data in-memory, for super fast processing.

Advertisement
Enterprise Security Spotlight

Syrian Electronic Army Hacks Financial Times
The Financial Times is the latest victim of the Syrian Electronic Army, a group that supports Syrian President Bashar al-Assad. The U.K.-based newspaper said a blog and its Twitter accounts were hacked.

Patch Tuesday Hyper Focuses on IE 8
Microsoft on Tuesday issued 10 security bulletins that fix 33 vulnerabilities. These updates include MS13-038, which will address the Internet Explorer 8 issue described in Security Advisory 2847140.

Surge of Venture Capital Buoys Tech Security Sector
With companies and governments spending billions to repel cyberthreats, a surge of venture capital is pouring into companies developing cybersecurity technologies, the front line of the conflict.

Advertisement
Navigation
Top Tech News
Home/Top News | Network Security | Microsoft/Windows | Linux/Open Source | Apple/Mac | Mobile Tech | World Wide Web
Tech Trends | Data Storage | Applications | Hardware | Unified Communications | Spam & Hackers | Chips & Processors
Cloud & Virtualization | Personal Tech | Press Releases
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2013 Top Tech News. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.