In-Depth

12 Microsoft Patches to Improve Security

Microsoft Security Response Center plans to publish twelve security bulletins that will address at least four

Get ready for the mother of all Patch Tuesdays. As of now, the Microsoft Security Response Center plans to publish twelve security bulletins, according to recent Microsoft advance notification.

At least four updates will address critical issues, Microsoft said—although Redmond was vague about just how many critical updates it plans to release. Microsoft lumped the bulletins into several groups: eight of which affect Windows, two of which affect Office, one of which affects both Windows and Office, and an assortment of others that affect Microsoft Data Access Components (MDAC), Microsoft's malware and antivirus technologies (Microsoft Antigen, Microsoft Windows Defender, and Microsoft Forefront), and Visual Studio, among others.

Of the five Windows bulletins, the advance notification says that, "The highest Maximum Severity rating for these is Critical." At least one Windows bulletin, one Office bulletin, along with the combined Windows-Office bulletin and the malware and antivirus bulletin, merit severity ratings of "Critical."

The advance notification isn't always the last word in Patch Tuesday deliverables, of course. Last month, for example, Microsoft yanked several promised Windows patches from its Patch Tuesday payload. Redmond typically pulls a patch if it discovers problems during testing, or if it identifies other issues.

The software giant didn't say whether this Tuesday's patch haul will include fixes for any of several Word zero-day exploits now in circulation; nor did Microsoft indicate if this Patch Tuesday payload will address an Excel zero-day attack that recently came to light.

With two Office-related bulletins in the offing, as well as a combined Windows and Office bulletin coming, it's possible Microsoft plans to patch these vulnerabilities.

Microsoft customers will also see an update of the Windows Malicious Software Removal Tool amongst the deliverables from this Patch Tuesday. In addition, Microsoft plans to distribute two non-security high-priority updates via Windows Update (WU) and Software Update Services (SUS); along with eight non-security high priority updates via Microsoft Update (MU) and Windows Server Update Services (WSUS).

About the Author

Stephen Swoyer is a Nashville, TN-based freelance journalist who writes about technology.

comments powered by Disqus

Featured

  • Windows Community Toolkit v8.2 Adds Native AOT Support

    Microsoft shipped Windows Community Toolkit v8.2, an incremental update to the open-source collection of helper functions and other resources designed to simplify the development of Windows applications. The main new feature is support for native ahead-of-time (AOT) compilation.

  • New 'Visual Studio Hub' 1-Stop-Shop for GitHub Copilot Resources, More

    Unsurprisingly, GitHub Copilot resources are front-and-center in Microsoft's new Visual Studio Hub, a one-stop-shop for all things concerning your favorite IDE.

  • Mastering Blazor Authentication and Authorization

    At the Visual Studio Live! @ Microsoft HQ developer conference set for August, Rockford Lhotka will explain the ins and outs of authentication across Blazor Server, WebAssembly, and .NET MAUI Hybrid apps, and show how to use identity and claims to customize application behavior through fine-grained authorization.

  • Linear Support Vector Regression from Scratch Using C# with Evolutionary Training

    Dr. James McCaffrey from Microsoft Research presents a complete end-to-end demonstration of the linear support vector regression (linear SVR) technique, where the goal is to predict a single numeric value. A linear SVR model uses an unusual error/loss function and cannot be trained using standard simple techniques, and so evolutionary optimization training is used.

  • Low-Code Report Says AI Will Enhance, Not Replace DIY Dev Tools

    Along with replacing software developers and possibly killing humanity, advanced AI is seen by many as a death knell for the do-it-yourself, low-code/no-code tooling industry, but a new report belies that notion.

Subscribe on YouTube