PowerPoint patch due next week

But don't forget Adobe's PDF fix.

Microsoft has confirmed it will deliver just one security update next Tuesday, namely a fix for PowerPoint which is probably the patch for a month-old bug that developers admitted they missed during stress testing.

The single update, which will be labelled "critical," Microsoft's highest threat ranking, is a big drop from last month, when the company issued eight updates that patched 23 vulnerabilities.

"Last month, Microsoft closed three of the four known outstanding vulnerabilities, and left us only one in-the-public-domain bug," said Andrew Storms, director of security operations at nCircle Network Security. The sole unpatched public flaw was the PowerPoint vulnerability Microsoft acknowledged 2 April in a security advisory that warned of ongoing attacks using rigged presentation files.

"The question, is there a pattern here, have they caught up?" asked Storms. "Could we have hit bottom?"

But he immediately dismissed that idea. "Don't think for a minute that I believe that," Storms said. "Microsoft has done a fantastic job of getting people to report [vulnerabilities] only to them, but that doesn't mean there are no other bugs. Frankly, I expected more than just the one."

As is Microsoft's practice, it released only the most general information about the upcoming security patch in the advance notification it posted on Thursday. Unlike the April security advisory, however, the early warning today noted that PowerPoint 2000, 2002, 2003 and 2007 will require patching; the advisory had not painted the newest version, PowerPoint 2007, with the bug brush.

Previously, Microsoft had admitted that the bug was in an older PowerPoint file format. The inclusion of PowerPoint 2007, Storms speculated, means that the new version may be affected when it tries to convert from an older format to the Office 2007 native format.

The last time Microsoft issued only one update on a Patch Tuesday was in January, when it fixed flaws in Windows' Server Message Block (SMB) file-sharing protocol. At the time, another security expert, Eric Schultze, the chief technology officer at Shavlik Technologies, called the bugs "super nasty."

"Don't get me wrong, I'm happy to have the PowerPoint patch," said Storms today.

A side benefit of the light Microsoft load is that it will make it easier for users and IT administrators to also deploy the anticipated Adobe Reader and Acrobat security updates. Adobe said last week that it had set 12 May, Microsoft's already-scheduled patch day, to release updates for a critical vulnerability in the popular PDF applications.

Storms was critical of Adobe's decision to slate the Reader and Acrobat updates on a day when people will be scrambling to apply Microsoft's fixes. "This makes it quite a bit easier to get the Adobe updates out," Storms said Thursday.

Microsoft will release the one security update at approximately 1 pm ET on 12 May.


What are your views on this subject? Use the form below to post a comment on this article up to 500 characters.


Characters remaining: 500

Related Security news

Microsoft denies building security 'backdoor' in Windows 7

Privacy organisations shouldn't read too much into NSA involvement it says

Pentagon expands exclusive deal with McAfee

Department of Defense uses McAfee products

Police arrest pair over global banking web scam

Man and woman arrested in Manchester for using notorious Zeus Trojan

Security star Fortinet sets price for IPO

Investors still have taste for tech.



Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Database security: Preventing enterprise data leaks at the source

IDC discusses the growing internal threats to business information, the impact of government regulations on the protection of data, and how enterprises must adopt database security best practices...

Download Whitepaper

Service-oriented security

SOA has become an integral part of enterprise software by providing a framework to efficiently develop software as services that is easily sharable, reusable, and integrated. No where is the need more apparent than in the Identity Management space. Welcome to the age of Service-Oriented Security (SOS).

Download Whitepaper

Data protection prospective vendor checklist

Organisations need a way to map business needs against all these challenges in procuring a technical solution. To help, SANS has developed the following Prospective Vendor Checklist.

Download Whitepaper

Unlock the power of the mainframe

This whitepaper presents the notion of CICS as an integration hub based on a component-based, service-oriented architecture supporting Web services. Highlights will review the challenges and contrasted support for Web services natively in CICS.

Download Whitepaper

Techworld UK - Technology - Business

COLT White Paper

Are all VoIP services the same?

Questions to ask your service provider to ensure you get the VoIP service you need
With careful choice of partner, your business can have all the advantages of VoIP access - reduced costs, flexibility and simplicity - without the drawbacks.
This white paper is your guide to ensure you get right the VoIP service and details the pitfalls which businesses would do well to avoid.

Download white paper
BMC

Ride the express lane in the journey to speed ITIL adoption

Explore the challenges in making the journey to ITIL and the criteria for selecting consulting services
By following ITIL practices, your IT organisation will become more closely integrated with the business. We recommend making the journey to ITIL in a sequence of six incremental steps, the phases of which are driven through execution of a strategic transformational roadmap.

Download white paper

Webcast: IT Financial Management: Cost Optimisation for Efficiency and Agility.
On Demand Webcast
Join this webcast to learn about the techniques and technologies that can help you prove the value of IT to the business by understanding the true cost of today's IT services and those that will be necessary to deliver future success.

Register Today

Site Map

IDG Network

* *