Microsoft preps six patches for next week

Microsoft preps six patches for next week

Microsoft Corp. announced Thursday it will release six security updates next week, the same number as in June, to patch problems in Windows, Office and the .Net Framework.

Three of the six bulletins scheduled for July 10 will be tagged "critical" -- Microsoft's highest rating -- while two will be labeled "important" and the sixth ranked "moderate." Vulnerabilities fixed by five of the six updates, however, are remote code executable, an indicator that usually means the bugs are in the most dangerous classification.

Because Microsoft limits the information it posts in the advanced notification -- even with the switch to a more detailed format that debuted last month -- it's impossible to tell why two of the bulletins harboring remote code executable flaws are rated as only "important."

Of the three updates judged "critical," one will fix Microsoft Excel, another will repair Windows 2000 Server and Windows Server 2003, and the third will patch .Net Framework 1.0, 1.1, and 2.0 in all currently supported versions of Windows -- Vista included.

The pair of "important" bulletins addresses issues in Publisher 2007 and Windows XP Professional SP2; the "moderate" update, meanwhile, is limited to Windows Vista. July marks the fourth month in a row that Microsoft has posted patches for its newest operating system, which was released to the public in January.

Four non-security updates dubbed "high priority" will also post Tuesday via Windows Update, Microsoft Update and Windows Server Update Services (WSUS).

Some clues about the vulnerabilities likely to be patched next week can be gleaned from third-party sources. The bulletin focused on Publisher 2007 may be a fix for a bug reported to Microsoft in late February by eEye Digital Security, for example. Secunia, meanwhile, has three disclosed-but-unpatched flaws in .Net Framework 1.0 in its database, but none are ranked higher than "moderately critical" by the Danish vulnerability tracker.

Assuming Microsoft releases all six updates, users will have faced 41 bulletins in the first half of 2007, two more than the 39 in the first seven months last year.

Tuesday's updates will be available for manual download from the Microsoft Web site about 1 p.m. EDT assuming the company issues them on its usual timetable.

Follow Us

Join the newsletter!


Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.



Access4 holds inaugural A/NZ Annual Conference

Access4 holds inaugural A/NZ Annual Conference

​Access4 held its inaugural Annual Conference in Port Douglass, Queensland, for Australia and New Zealand from 9-11 October, hosting partners from across the region with presentations on Access4 product updates, its 2023 Partner of the Year awards and more.

Access4 holds inaugural A/NZ Annual Conference
Show Comments