http://www.theregister.co.uk/Print/2014/11/07/november_patch_tuesday_advistory/



Microsoft warns of super-sized Patch Tuesday next week

More security bulletins in November than in any prior month

By *Neil McAllister*
<http://forms.theregister.co.uk/mail_author/?story_url=/2014/11/07/november_patch_tuesday_advistory/>

Posted in Data Centre <http://www.theregister.co.uk/data_centre/>, 7th
November 2014 08:42 GMT <http://www.theregister.co.uk/2014/11/07>

It's getting close to security update time in Redmond yet again, and
Microsoft has given notice that Windows and Office users can expect another
nice, big pile of fixes on November's Patch Tuesday.

The software giant gave advance notice
<https://technet.microsoft.com/library/security/ms14-nov> of no less than
16 security bulletins to be addressed on November 11, five of which have
been flagged as "critical." Nine more are marked as "important" and the
remaining two are considered "moderate" risks.

"This is the highest bulletin count we have seen from Microsoft this year,"
Chris Goettel, product manager for IT management firm Shavlik, told *El Reg*
via email. May and August's Patch Tuesdays each featured nine bulletins.

One of November's critical bulletins pertains to all supported versions of
Internet Explorer, ranging from IE11 all the way back to IE6 running on
Windows Server 2003 SP2. IE patches have become a staple of Patch Tuesday,
and if past months are any indication, this bulletin is likely to address
multiple vulnerabilities.

The other critical bulletins address bugs in Windows itself, although just
how severe the flaws are depends on which version of the OS you're running.
No version is completely safe, however – even the Windows 10 Technical
Preview will need to be patched.

Four of the five critical bugs are said to allow remote code execution,
while the last could allow an attacker to gain administrative privilege on
a vulnerable machine. Several of the less-severe flaws allow privilege
elevation, as well, while others allow attackers to bypass OS security
features.

Some of this month's bulletins are narrowly focused. Bulletin 6 pertains to
Microsoft Office 2007 exclusively, for example, while Bulletin 10 affects
some components of SharePoint Foundation 2010 SP2 and Bulletin 12 affects
Exchange Server 2007, 2010 and 2013.

As usual, the fixes will all be made available via Windows Update, which
means they will be applied automatically for most users. Microsoft is
encouraging those who have disabled automatic updates to apply them
promptly.

In past months, Adobe has also timed an update to its Flash plugin to
coincide with Microsoft's patch dump. There's been no word of any such
update for this month so far, but if Adobe has fixes up its sleeve, you
should plan to apply those on Tuesday, as well. ®

*Related stories *

·         Crypto collision used to hijack Windows Update goes mainstream
<http://www.theregister.co.uk/2014/11/05/md5_hash_collision/>(5 November
2014)

http://www.theregister.co.uk/2014/11/05/md5_hash_collision/

·         UK consumers particularly prone to piss-poor patching
<http://www.theregister.co.uk/2014/10/30/uk_consumers_prone_to_particularly_patchy_patching/>(30
October 2014)

http://www.theregister.co.uk/2014/10/30/uk_consumers_prone_to_particularly_patchy_patching/

·         Bad dog: Redmond's new IE tool KILLS POODLE with one shot
<http://www.theregister.co.uk/2014/10/29/microsoft_poodle_fixit_for_ie/>(29
October 2014)

http://www.theregister.co.uk/2014/10/29/microsoft_poodle_fixit_for_ie/

·         Microsoft pulls *another* dodgy patch
<http://www.theregister.co.uk/2014/10/20/microsoft_pulls_ianotheri_dodgy_patch/>(20
October 2014)

http://www.theregister.co.uk/2014/10/20/microsoft_pulls_ianotheri_dodgy_patch/

·         Internet Explorer stars in monster October Patch Tuesday
<http://www.theregister.co.uk/2014/10/10/ie_adobe_oracle_october_patch_tuesday_preview/>(10
October 2014)

http://www.theregister.co.uk/2014/10/10/ie_adobe_oracle_october_patch_tuesday_preview/




__._,_.___
 ------------------------------
Posted by: "beowulf" <[email protected]>
------------------------------


 Visit Your Group
<https://groups.yahoo.com/neo/groups/grendelreport/info;_ylc=X3oDMTJmajZ0aGEwBF9TAzk3MzU5NzE0BGdycElkAzIwMTk0ODA2BGdycHNwSWQDMTcwNTMyMzY2NwRzZWMDdnRsBHNsawN2Z2hwBHN0aW1lAzE0MTU1NjA4NjM->


 [image: Yahoo! Groups]
<https://groups.yahoo.com/neo;_ylc=X3oDMTJldDhzdmc1BF9TAzk3NDc2NTkwBGdycElkAzIwMTk0ODA2BGdycHNwSWQDMTcwNTMyMzY2NwRzZWMDZnRyBHNsawNnZnAEc3RpbWUDMTQxNTU2MDg2Mw-->
• Privacy <https://info.yahoo.com/privacy/us/yahoo/groups/details.html> •
Unsubscribe <[email protected]?subject=Unsubscribe>
• Terms of Use <https://info.yahoo.com/legal/us/yahoo/utos/terms/>

__,_._,___

-- 
-- 
Thanks for being part of "PoliticalForum" at Google Groups.
For options & help see http://groups.google.com/group/PoliticalForum

* Visit our other community at http://www.PoliticalForum.com/  
* It's active and moderated. Register and vote in our polls. 
* Read the latest breaking news, and more.

--- 
You received this message because you are subscribed to the Google Groups 
"PoliticalForum" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to