Microsoft promises huge patch day next week

Slates 11 updates for Windows, IE, Active Directory, Office and Host Integration Server

Microsoft Thursday said it will issue 11 security updates next week -- the same number it shipped in August when pushed out the most patches in 18 months -- to fix bugs in Windows, Active Directory, Internet Explorer (IE), Office and Host Integration Server.

Four of the 11 updates will be labeled "critical," Microsoft's highest threat ranking, with six pegged "important," the next-lowest rating, and one tagged as "moderate."

As is Microsoft's practice, it released only the most general information about the upcoming security patches in the advance notification it posted Thursday. Among the details that the company provides are the affected software, the severity of the security problem and the components involved.

Seven of the 11 updates will address vulnerabilities that Microsoft acknowledged can be used to execute remote code, a description that generally means hackers could exploit those vulnerabilities to inject their own malicious code into vulnerable PCs, often by convincing users to open a file attachment or tricking them into visiting a rogue Web site. All four of the critical updates were marked with Microsoft's "Remote Code Execution" label, as were three of the important bulletins.

Bugs in Active Directory, Internet Explorer, Excel and Microsoft Host Integration Server were all tagged critical.

The Active Directory fix will apply only to Windows 2000 Server, said Microsoft, which has patched the component several times, most recently in June when it fixed a broader problem in validating client LDAP requests.

On the other hand, the patch for Host Integration Server (HIS) is a first for that software, a little-known enterprise product that connects Windows-based networks to IBM mainframe and AS/400 systems. HIS 2000, HIS 2004 and HIS 2006 are all affected, said Microsoft.

Based on the versions impacted, the Excel update will likely patch a file format problem; both Windows and Mac editions of the spreadsheet program will have to be patched, said Microsoft. When that has happened in the past, the update has usually addressed file format bugs.

The IE patch, meanwhile, will fix flaws rated critical in IE5 and IE6, but which Microsoft ranked as only important for the newer IE7. According to Danish bug tracker Secunia, which lists several vulnerabilities in IE that need attention, the most-pressing problem is a cross-domain scripting bug in IE6 reported more than three months ago.

Other updates, including all six marked important, will address bugs in various versions of Windows; the one bulletin labeled moderate affects only Office XP Service Pack 3 (SP3).

In a related note, Microsoft said last month that Tuesday's updates would be the last for Office 2003 SP2; after next week, the company will only support that version of Office as Service Pack 3.

Microsoft will release the 11 security updates at approximately 1pm USEDT on October 14.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags microsoft patches

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Gregg Keizer

Computerworld
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

David Coyle

Brother PocketJet PJ-773 A4 Portable Thermal Printer

I rate the printer as a 5 out of 5 stars as it has been able to fit seamlessly into my busy and mobile lifestyle.

Kurt Hegetschweiler

Brother PocketJet PJ-773 A4 Portable Thermal Printer

It’s perfect for mobile workers. Just take it out — it’s small enough to sit anywhere — turn it on, load a sheet of paper, and start printing.

Featured Content

Product Launch Showcase

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?