Top Tech News

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
News & Product Reviews for Tech Leaders
Commvault Simpana® 10
Protect, manage, access, and
realize the untapped value of data.

www.commvault.com
Thursday, June 20th 
Introducing Simpana® 10 software
Home
Network Security
Microsoft/Windows
Linux/Open Source
Apple/Mac
Mobile Tech
World Wide Web
Tech Trends
Data Storage
Applications
Hardware
Unified Communications
Spam & Hackers
Chips & Processors
Cloud & Virtualization
Personal Tech
Press Releases
 
Free Newsletters
Top CIO News
 
Mobile Tech Today
 

Advertisement


Network Security

Microsoft Patch Tuesday Shows Secure Coding Pays Off

Microsoft Patch Tuesday Shows Secure Coding Pays Off
December 12, 2012 10:18AM

Bookmark and Share
Security researcher Paul Henry said it was great to see Microsoft's Secure Coding Initiative paying off, reducing the number of vulnerabilities in its software, resulting in an easier time for IT at Patch Tuesday time. Over the year, Microsoft Patch Tuesday released 35 critical security bulletins, 46 important bulletins and two moderate bulletins.

CommVault is a data and information management software company dedicated to providing organizations worldwide with a radically better way to manage data and information. Their unique Solving Forward philosophy allows them to deliver complete solutions with infinite scalability and unprecedented control over data and costs. Be among the first to experience Simpana 10 software. Click here now.

Microsoft Relevant Products/Services's last Patch Tuesday of 2012 rolled out seven patches. Five of them are rated critical and two are rated important. The good news is: none are under active attack.

With December's Patch Tuesday, Microsoft has rolled out 83 security bulletins in 2012. That's significantly down from the 100 security bulletins Redmond released in 2011. Microsoft released 117 security bulletins in 2010.

"Maybe even more important than the raw numbers is the more regular release rhythm that Microsoft set this year," said Wolfgang Kandek, CTO at Qualys. "We see this as a clear sign of a more mature process."

Prioritizing the Patches

Looking at December's patches, five of this month's bulletins are rated as critical. That means an attacker can use the vulnerabilities Microsoft is fixing to gain complete control over the victim's machine.

"Of the five, we think that MS12-079, a bulletin for Microsoft Word, is the most important. The attack can be accomplished through e-mail using a flaw in the Rich Text Format," Kandek told us. "An attacker can gain control of a computer Relevant Products/Services without end user interaction because Microsoft Outlook automatically displays the malicious text in the Preview Pane."

Kandek pointed to a potential work-around: manually configuring the preview pane in Outlook's Trust Center to use plain text only. The downside is you lose a significant amount of functionality by opting for this workaround.

Kandek put the Internet Explorer bulletin MS12-077 in a close second with regard to IT patching priorities. MS12-077 addresses vulnerabilities in IE 9 and 10, the newest versions of IE that run under Vista, Windows 7 and Windows 8.

"Here, an attacker would have to lure the attack target to browse to a malicious Web page," Kandek said. "This is a tad harder than sending the target a simple e-mail, another common attack method."

Secure Coding Initiative Pays Off

Paul Henry, a security and forensic analyst for Lumension, also pulled the camera back and took a wide view of 2012. With the multitude of third-party application patching needed this year from the likes of Adobe, Java and even Apple, he said, you likely didn't notice Microsoft put out 20 percent fewer patches in 2011.

Over the year, Microsoft Patch Tuesday released 35 critical bulletins, 46 important bulletins and two moderate bulletins. Henry said it was great to see Microsoft's Secure Coding Initiative paying off, reducing the number of vulnerabilities in its software Relevant Products/Services, resulting in an easier time for IT at Patch Tuesday time.

"A look back over the last couple of years proves interesting. In 2011, January had two bulletins, while February had 12. March then went back down to three, but April went up to 17. May had two and June went back up to 16," Henry said.

"In contrast, January of this year had seven patches, February had nine, then six in both March and April, and seven in both May and June. In fact, only one month -- September, at three -- was lower than six or higher than nine. The degree of consistency makes it easier for IT to plan out the time and effort they'll need to spend on Patch Tuesday each month."

Tell Us What You Think
Comment:

Name:

Norm:

Posted: 2012-12-13 @ 10:29am PT
@Shickadee: Mine went smoothly. You might want to try again, but also report the problem directly to Microsoft. Good luck.

Shickadee:

Posted: 2012-12-13 @ 10:26am PT
This December's update couldn't make it past the 7th of twelve updates. After waiting more than 1/2 a day for it to complete, I finally chanced it and restarted my computer. Thankfully it recovered okay. This is the 1st time this has happened, with all the Windows 7 updates. Has anyone else had this problem?

Advertisement



 Network Security
1. Snowden To Dish More Info on NSA
2. Prism's Secret: Bigger Data Seizure
3. Keeping Your Data Safe from Spying
4. Google Uses Secure FTP for NSA
5. Google Reports Iran Phishing Attacks


advertisement


 Most Popular Articles
1. Will BlackBerry Fans Flock to the Q10 and Its Keyboard?
2. VMware Brings Analytics to Log Data Apps
3. New Facebook Data Center Uses All Home-Grown Servers
4. AMD Will Make Chips for Android, Chrome Devices
5. Going Mobile Means Productivity Gains for Some SMBs


advertisement

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  CRM Booming, BPM Critical Too
  Is Cumulus OS Really a Cisco-Killer?
  Dish Network Drops Pursuit of Sprint
  Snowden To Dish More Info on NSA
  Google Clears the Way for Stock Split

 Technology Marketplace

BYOD & MDM
Forrester Research Inc., Report: BYOD from AT&T. Make everyone more efficient.
 
Cloud & Virtualization
Brocade technologies help enable the full benefits of virtualization.
 
Contact Centers
Unlock the potential in your people with Microsoft Dynamics
Improve your customer relationships with Microsoft Dynamics
 
Customer Service
Unlock the potential in your people with Microsoft Dynamics
Improve your customer relationships with Microsoft Dynamics
 
Data Centers
Your Next Generation Data Center Is Here! Vblock™ Systems from VCE
 
Data Security
Simpana® 10 software: an exponential leap forward
 
Data Storage
Brocade makes it easier to deploy, manage, and scale networks.
 
Enterprise Hardware
Panasonic Toughbook® mobile computers are built to keep you running.
 
Enterprise Software
Simpana® 10 software: an exponential leap forward
 
Hardware
The best document scanner for you? Try KODAK's scanner selector
 
Innovation
The best document scanner for you? Try KODAK's scanner selector
 
Laptops & Tablets
Panasonic Toughbook® mobile computers are built to keep you running.
 
Network Security
Brocade makes it easier to deploy, manage, and scale networks.
 
Navigation
Top Tech News
Home/Top News | Network Security | Microsoft/Windows | Linux/Open Source | Apple/Mac | Mobile Tech | World Wide Web
Tech Trends | Data Storage | Applications | Hardware | Unified Communications | Spam & Hackers | Chips & Processors
Cloud & Virtualization | Personal Tech | Press Releases
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2013 Top Tech News. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.