Patch Patrol

Offering the latest information on current threats and vulnerabilities to help IT managers better protect and secure their networks.

Posted on February 14, 2012 | Jason Miller | No Comments | Patch Management, Patch Patrol

February 2012 Patch Tuesday Overview

Jason Miller

Microsoft has released nine new security bulletins for the February 2012 edition of Patch Tuesday.  This Patch Tuesday is typically marked as a ‘heavy’ release month and includes nine new security bulletins addressing 21 vulnerabilities.

There are two bulletins that administrators should look to patch immediately.  Both of these bulletins address vulnerabilties that have the potential for drive-by attack scenarios from websites.

First up is Microsoft security bulletin MS12-010.  This bulletin affects all supported Microsoft Internet Explorer browsers and addresses four vulnerabilities in the browser.  As is the case with most, if not all Internet Browsers, it is …

Read More»

Posted on February 9, 2012 | Jason Miller | No Comments | Patch Management

February 2012 Patch Tuesday Advanced Notification

Jason Miller

Microsoft has announced their February 2012 Advanced Notification for the upcoming Patch Tuesday.  Microsoft is planning to release nine security bulletins fixing 21 vulnerabilities.

Security Bulletin Breakdown:

4 bulletins are rated as Critical
5 bulletins are rated as Important
7 vulnerabilities could lead to Remote Code Execution
2 vulnerabilities could lead to Elevation of Privilege

Affected Products:

All supported Microsoft Operating systems
All supported Internet Explorer browsers
Visio Viewer 2010
SharePoint Server 2010
SharePoint Foundation 2010
Silverlight 4

There has been no word of other vendors planning to release new security bulletins, but we are constantly monitoring to find any other vendors planning on joining Microsoft’s Patch Tuesday.

I will be talking …

Read More»

Posted on January 10, 2012 | Jason Miller | 2 Comments | Patch Management, Patch Patrol

January 2012 Patch Tuesday Overview

Jason Miller

Microsoft is starting off the new year with seven new security bulletins released for the January 2012 Patch Tuesday.  These seven new security bulletins address eight vulnerabilities.

The primary bulletin administrators should patch first is MS12-004.  This security bulletin addresses two vulnerabilities with Windows Media types.  Opening a malicious media or MIDI file on an unpatched system could allow an attacker to gain full control of the system.  As media files are extremely popular for viewing and sharing, administrators should patch this bulletin on their workstation machines as soon as possible.  It is important to note that …

Read More»

Posted on January 5, 2012 | Jason Miller | No Comments | Patch Management, Patch Patrol

January 2012 Patch Tuesday Advanced Notification

Jason Miller

Microsoft is kicking off the 2012 year with seven new Microsoft Security Bulletins.  Just announced in their advanced notification for the January 2012 Patch Tuesday, these seven security bulletins will address eight vulnerabilities.

Security Bulletin Breakdown:

1 bulletin is rated as Critical
6 bulletins are rated as Important
3 vulnerabilities could lead to Remote Code Execution
1 vulnerability could lead to Security Feature Bypass
2 vulnerabilities could lead to Information Disclosure
1 vulnerability could lead to Elevation of Privilege

Affected Products:

All supported Microsoft Operating Systems
Microsoft Developer Tools and Software

 

This Tuesday will also be a good chance to install the out-of-band security update (MS11-100) on …

Read More»

Posted on December 13, 2011 | Jason Miller | No Comments | Patch Management, Patch Patrol

Patches Make for Good Gifts

Jason Miller

Tis the season of good friends, good food, good conversation and of course patching your network.  Today marks the final Patch Tuesday of 2011, and it’s a big one. Microsoft is giving the gift of 13 security bulletins addressing 19 vulnerabilities to add to the stress of this holiday season.  Not to be outdone by Microsoft, other software vendors such as Google and Adobe are also joining in on the season of giving by releasing updates of their own.  This combination of Microsoft and non-Microsoft patch releases will definitely keep us busy this season.

On the Microsoft side, there …

Read More»

Posted on December 8, 2011 | Jason Miller | No Comments | Patch Management, Patch Patrol

December 2011 Patch Tuesday Advanced Notification

Jason Miller

Microsoft has released their advanced notification for the December 2011 edition of Patch Tuesday.  Microsoft is giving the gift of 14 security bulletins addressing 20 vulnerabilities this holiday season.

Security Bulletin Breakdown:

3 bulletins rated as Critical
11 bulletins rated as Important
10 vulnerabilities could lead to Remote Code Execution
1 vulnerability could lead to Information Disclosure
3 vulnerabilities could lead to Elevation of Privilege

 

Affected Products:

All supported Microsoft Operating systems
Publisher 2003, 2007
Excel 2003
PowerPoint 2007, 2010
Office 2007, 2010
PowerPoint Viewer 2007
Office Compatibility Pack 2007

 

On the non-Microsoft front, Adobe released a security advisory (APSA11-04) for a zero-day vulnerability affecting Adobe Acrobat/Reader 9/10 on December 6th.  …

Read More»

Posted on November 8, 2011 | Jason Miller | No Comments | Patch Management, Patch Patrol

November 2011 Patch Tuesday Overview

Jason Miller

Microsoft has released four new security bulletins for this edition of Patch Tuesday.  These four security bulletins address four vulnerabilities.

The first bulletin administrators should address is MS11-083.  This bulletin addresses one vulnerability in Windows TCP/IP.  If an attacker sends a stream of malicious User Datagram Protocol (UDP) network packets to an unpatched machine, the attacker could gain control over the affected system.  With this type of an attack scenario, alarms could be raised about the potential of a vulnerability that is used in a worm.  However, there are a few items that will make it difficult …

Read More»

Posted on November 7, 2011 | Chris Goettl | No Comments | IT Management, Patch Management, Product Blog, Tips

VMware vCenter Protect Essentials Plus available for download

Chris Goetti

It is patch week once again, but before the patch announcements and Patch Tuesday webinar start to fill your week I wanted to let you know what a couple hundred of our customers have already found out.  VMware vCenter Protect Essentials Plus 8.0 (formerly Shavlik NetChk Protect) is now available.  For those of you who have not seen the new features of the latest release they are focused on making day to day IT Management easier.

Check out the ITScripts feature and integration with RDP which provide some handy and quick solutions for any …

Read More»

Posted on November 3, 2011 | Jason Miller | No Comments | Patch Management, Patch Patrol

November 2011 Patch Tuesday Advanced Notification

Jason Miller

Microsoft has released their advanced notification for the upcoming November edition of Patch Tuesday.  Microsoft is planning to release four new security bulletins addressing four  vulnerabilities.

Security Bulletin Breakdown:

1 bulletin rated as Critical
2 bulletins rated as Important
1 bulletin rated as Moderate
2 vulnerabilities fixed could lead to Remote Code Execution
1 vulnerability fixed could lead to Elevation of Privilege
1 vulnerability fixed could lead to Denial of Service

 Affected Products:

All supported Microsoft Operating Systems

 

On the non-Microsoft front, be prepared for new versions of products in the Mozilla family.  New versions of Firefox, Thunderbird and SeaMonkey should be available on Patch Tuesday.

I will be …

Read More»

Posted on October 11, 2011 | Jason Miller | No Comments | Patch Management, Patch Patrol

October 2011 Patch Tuesday Overview

Jason Miller

Microsoft has released eight new security bulletins in their October 2011 version of Patch Tuesday.  These eight new security bulletins address 23 vulnerabilities.

The bulletin administrators should look at patching first is the bi-monthly cumulative update for Microsoft Internet Explorer.  Security bulletin MS11-081 addresses eight individual vulnerabilities in Internet Explorer.  A user visiting a malicious web page with an unpatched Internet Explorer browser could lead to remote code execution.  As with every security update for Internet browsers (Microsoft or other browser vendors), patching browsers will be top priority because the vulnerabilities fixed with each security bulletin release …

Read More»