Top Tech News

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
News & Product Reviews for Tech Leaders
Brocade delivers
cloud-optimized networking solutions
to deploy, manage, and scale networks.

www.brocade.com
Friday, May 24th 
Panasonic Toughbook® mobile computers
Home
Network Security
Microsoft/Windows
Linux/Open Source
Apple/Mac
Mobile Tech
World Wide Web
Tech Trends
Data Storage
Applications
Hardware
Unified Communications
Spam & Hackers
Chips & Processors
Cloud & Virtualization
Personal Tech
Press Releases
 
Free Newsletters
Top CIO News
 
Mobile Tech Today
 

Advertisement


Network Security

Microsoft Patch Tuesday Shows Secure Coding Pays Off

Microsoft Patch Tuesday Shows Secure Coding Pays Off
December 12, 2012 10:18AM

Bookmark and Share
Security researcher Paul Henry said it was great to see Microsoft's Secure Coding Initiative paying off, reducing the number of vulnerabilities in its software, resulting in an easier time for IT at Patch Tuesday time. Over the year, Microsoft Patch Tuesday released 35 critical security bulletins, 46 important bulletins and two moderate bulletins.

Panasonic Toughbook® mobile computers are engineered to withstand drops, spills, dust and grime, and to perform in the harshest environments. Rugged reliability, low cost of ownership and accolades from reviewers are just a few of the reasons why Toughbook computers keep winning over the world's toughest users. Click here to learn more.

Microsoft Relevant Products/Services's last Patch Tuesday of 2012 rolled out seven patches. Five of them are rated critical and two are rated important. The good news is: none are under active attack.

With December's Patch Tuesday, Microsoft has rolled out 83 security bulletins in 2012. That's significantly down from the 100 security bulletins Redmond released in 2011. Microsoft released 117 security bulletins in 2010.

"Maybe even more important than the raw numbers is the more regular release rhythm that Microsoft set this year," said Wolfgang Kandek, CTO at Qualys. "We see this as a clear sign of a more mature process."

Prioritizing the Patches

Looking at December's patches, five of this month's bulletins are rated as critical. That means an attacker can use the vulnerabilities Microsoft is fixing to gain complete control over the victim's machine.

"Of the five, we think that MS12-079, a bulletin for Microsoft Word, is the most important. The attack can be accomplished through e-mail using a flaw in the Rich Text Format," Kandek told us. "An attacker can gain control of a computer Relevant Products/Services without end user interaction because Microsoft Outlook automatically displays the malicious text in the Preview Pane."

Kandek pointed to a potential work-around: manually configuring the preview pane in Outlook's Trust Center to use plain text only. The downside is you lose a significant amount of functionality by opting for this workaround.

Kandek put the Internet Explorer bulletin MS12-077 in a close second with regard to IT patching priorities. MS12-077 addresses vulnerabilities in IE 9 and 10, the newest versions of IE that run under Vista, Windows 7 and Windows 8.

"Here, an attacker would have to lure the attack target to browse to a malicious Web page," Kandek said. "This is a tad harder than sending the target a simple e-mail, another common attack method."

Secure Coding Initiative Pays Off

Paul Henry, a security and forensic analyst for Lumension, also pulled the camera back and took a wide view of 2012. With the multitude of third-party application patching needed this year from the likes of Adobe, Java and even Apple, he said, you likely didn't notice Microsoft put out 20 percent fewer patches in 2011.

Over the year, Microsoft Patch Tuesday released 35 critical bulletins, 46 important bulletins and two moderate bulletins. Henry said it was great to see Microsoft's Secure Coding Initiative paying off, reducing the number of vulnerabilities in its software Relevant Products/Services, resulting in an easier time for IT at Patch Tuesday time.

"A look back over the last couple of years proves interesting. In 2011, January had two bulletins, while February had 12. March then went back down to three, but April went up to 17. May had two and June went back up to 16," Henry said.

"In contrast, January of this year had seven patches, February had nine, then six in both March and April, and seven in both May and June. In fact, only one month -- September, at three -- was lower than six or higher than nine. The degree of consistency makes it easier for IT to plan out the time and effort they'll need to spend on Patch Tuesday each month."

Tell Us What You Think
Comment:

Name:

Norm:

Posted: 2012-12-13 @ 10:29am PT
@Shickadee: Mine went smoothly. You might want to try again, but also report the problem directly to Microsoft. Good luck.

Shickadee:

Posted: 2012-12-13 @ 10:26am PT
This December's update couldn't make it past the 7th of twelve updates. After waiting more than 1/2 a day for it to complete, I finally chanced it and restarted my computer. Thankfully it recovered okay. This is the 1st time this has happened, with all the Windows 7 updates. Has anyone else had this problem?

Advertisement

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  Google Buys Into Wind-Power Drones
  Kim Dotcom Claims Two-Factor Patent
  HP PCs Aim for Flexibility, Mobility
  Twitter Hoping To Halt Hack Attacks
  Viva Movil! Buy a Phone from J.Lo

 Technology Marketplace

BYOD & MDM
Forrester Research Inc., Report: BYOD from AT&T. Make everyone more efficient.
 
Cloud & Virtualization
Brocade technologies help enable the full benefits of virtualization.
Riverbed Stingray Traffic Manager on Amazon Web Services
 
Contact Centers
Unlock the potential in your people with Microsoft Dynamics
Unlock the potential in your people with Microsoft Dynamics
 
Customer Service
Unlock the potential in your people with Microsoft Dynamics
Unlock the potential in your people with Microsoft Dynamics
 
Data Security
Simpana® 10 software: an exponential leap forward
 
Data Storage
Brocade makes it easier to deploy, manage, and scale networks.
 
Enterprise Software
Simpana® 10 software: an exponential leap forward
 
Hardware
Rugged and reliable Panasonic Toughbook® mobile computers.
 
Laptops & Tablets
Rugged and reliable Panasonic Toughbook® mobile computers.
 
Mobile Gadgets
Rugged and reliable Panasonic Toughbook® mobile computers.
 
Network Security
Brocade makes it easier to deploy, manage, and scale networks.
 
Mobile Enterprise Spotlight

Viva Movil! Buy a Phone from J.Lo
Latina pop sensation and entrepreneur Jennifer Lopez is teaming with Verizon Wireless on a new 4G LTE network and wireless service dubbed Viva Movil by Jennifer Lopez, aimed at the U.S. Latino market.

Samsung Sells 10 Million Galaxy S IVs -- Four Every Second
The new Galaxy S IV smartphone from Samsung is off to a strong start. The South Korean manufacturer has announced that global sales for the device have exceeded 10 million units in one month.

Google Adds Conversational Search to Chrome
If you like chatting with Siri, sending voice texts while driving or telling your Xbox when to pause or rewind a DVD, you're going to enjoy the upgrade to Google's Chrome browser.

Advertisement
Enterprise Hardware Spotlight

Newest HP PCs Aim for Flexibility, Mobility
Hewlett-Packard is hoping its latest PC innovations will make its competitors envious. The new HP Envy Rove20 is the company's first mobile all-in-one PC, complete with a built-in battery and touch technology.

Dell Kills Its Public Cloud Effort, Will Offer Partner Marketplace
Putting the kibosh on its efforts to build out a public cloud, Dell has announced a new program to offer a choice of cloud Infrastructure-as-a-Service through a central marketplace of partners.

Dell's Dismal Quarter Shows PC Maker's Challenges
Dell's financial decay worsened during its latest quarter as the company slashed its personal computer prices in response to the growing popularity of smartphones and tablets in the beleaguered industry.

Advertisement
Navigation
Top Tech News
Home/Top News | Network Security | Microsoft/Windows | Linux/Open Source | Apple/Mac | Mobile Tech | World Wide Web
Tech Trends | Data Storage | Applications | Hardware | Unified Communications | Spam & Hackers | Chips & Processors
Cloud & Virtualization | Personal Tech | Press Releases
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2013 Top Tech News. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.