Ring in the New Year with Seven Microsoft Patches

If you, like me, are still basking in the afterglow of a relaxing holiday respite, the relentless re-introduction of Microsoft Patch Day may seem like a harsh reminder of some of the drudgery suffered by an InfoSec professional. Don’t get me wrong! Patching is one of the most effective ways of keeping your systems safe. Yet, its ceaseless nature can’t help but put me into a Sisyphean mood.

That said, here comes another round of Microsoft patches, so get ready to push that security boulder back up another hill next Tuesday.

According to their first advanced Notification post for the year, Microsoft plans to release seven new security bulletins next Tuesday, as part of their January Patch Day. The bulletins will include updates to fix security vulnerabilities in Windows, Office, the .NET Framework, and some of Microsoft’s Server Software. Microsoft rates two of the  bulletins as Critical, and the rest as Important.

Microsoft Patch Day: January 2013

Regular followers might notice that a fix for the recent Internet Explorer (IE) zero day vulnerability is missing from Microsoft’s expected updates. Researchers discovered this issue very recently, so I frankly wasn’t expecting a fix yet. It wouldn’t surprise me though if Microsoft releases an “out-of-cycle” update later in the month. In any case, if you applied the  FixIt workaround I recommended previously, you should be fine. As an aside, WatchGuard’s signature writers developed a signature for the known exploit, so if you use our IPS service you are further protected.

I’ll post more information about Microsoft’s updates next week, so keep posted. — Corey Nachreiner, CISSP (@SecAdept)

About Corey Nachreiner

Corey Nachreiner has been with WatchGuard since 1999 and has since written more than a thousand concise security alerts and easily-understood educational articles for WatchGuard users. His security training videos have generated hundreds of letters of praise from thankful customers and accumulated more than 100,000 views on YouTube and Google Video. A Certified Information Systems Security Professional (CISSP), Corey speaks internationally and is often quoted by other online sources, including C|NET, eWeek, and Slashdot. Corey enjoys "modding" any technical gizmo he can get his hands on, and considers himself a hacker in the old sense of the word.

Trackbacks/Pingbacks

  1. WatchGuard Security Week in Review: Episode 46 – IE 0day | WatchGuard Security Center - January 4, 2013

    [...] Next week’s Patch Day details - WGSC [...]

  2. Microsoft Black Tuesday: Updates Correct .NET and MSXML Flaws | WatchGuard Security Center - January 8, 2013

    [...] promised, Microsoft released seven security bulletins and software updates today, two of which they rate as [...]

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Connecting to %s

Follow

Get every new post delivered to your Inbox.

Join 7,114 other followers

%d bloggers like this: