Huge “Patch Tuesday” Coming–17 Bulletins–64 Vulnerabilities Addressed

A really HUGE Update is coming on Tuesday!

17  patches are coming: 8 rated “Critical” and 9 rated “Important” with fixes for 64 documented vulnerabilities across Microsoft Windows, Microsoft Office, Internet Explorer, Visual Studio, .NET Framework and GDI+.

From Pete Voss’s Technet Blog:

 

“This month we'll be closing some issues that Microsoft has already previously spoken to, including the SMB Browser (Critical) issue publicly disclosed Feb. 15. Microsoft assessed the situation and reported that although the vulnerability could theoretically allow Remote Code Execution, that was extremely unlikely.  To this day, we have seen no evidence of attacks.

We are also planning a fix for the MHTML vulnerability in Windows, rated Important. We alerted people to this issue with Security Advisory 2501696 (including a Fix-It that fully protected customers once downloaded) back in late January. In March, we updated the advisory to let people know we were aware of limited, targeted attacks.

The bulletin release scheduled for the second Tuesday of the month, April 12, at approximately 10 a.m. PDT.”

Voss didn’t address the vulnerabilities discovered in the “Pwn2Own” contest.

People, please get the updates and patches. Also, please update your Programs: Stardock’s, and others…. This is an important key to your security, and a fast, reliable computer.

118,836 views 81 replies
Reply #1 Top

Oh great, something else to screw up Stardock products... :P

Reply #2 Top

I guess there are rewards for some of us, I don't use Office or Visual Studio.  I took a look at what was being updated and most of them were with those two, or atleast from what I could tell.  :S

Reply #3 Top

There are very important fixes being pushed... Like MHTML, for one. I advise everyone to do the relevant patches!

Reply #4 Top

Oh, I always do the updates. 

Reply #5 Top

I always do the updates as well with the exception of any related to WGA and activation stuff. No need to have Windows calling home every month. My copy is legit - I just value my privacy.

Reply #6 Top

The Doc suggestions are very good,and iI hope everyone will follow them.

Besides,I want to tell one thing more:please,download Secunia PSI http://secunia.com/vulnerability_scanning/personal/ ,that scan your PC and inform you about any software and plugin vulnerabilities,O.S.missing security patches,browsers vulnerabilities,end-of-life progs (no more supported)elements(please NOTE,all end-of-life progs elements are potential vulnerabilities,and needs to be deleted from the system),and tell you all the steps to get the needed patches,if available.,by Secunia PSI itself.

On Secunia website you can easily get all kind of info you want about.I'm running the last version of Kaspersky Internet Security 2011,and among his tools there is a vulnerability scanner too.Well,just to give an idea,this tool is based on Secunia database,that is absolutely huge at the moment(and probably in the future as well)Secunia PSI is the best prog so far in his sector.

Just give it a try! 

Reply #7 Top

the link in post 6

I think the admins need to look at

kids come here to and this link is linking to porn sites ... Well I really can't say as I did not click on any of them but with links of porn like wording

 

Reply #8 Top

Yup, saw the same.  Maybe inthebloodofeden can take care of that.  :-"

Reply #9 Top

@inthebloodofeden, Out of curiosity I went to Secunia and checked out the PSI. Did the install and the return is all programs up to date save one, my PS7. Says I need a security patch for it and it needs to be manually installed. If PS7 is an end-of-life program then why does Adobe still sell it for $699.00? Go figure. 

Hang on: I clicked on the link and it took me to Secunia's website. Not to a porn site. I still have it up in a separate tab. I can show it to you if you like.

http://secunia.com/vulnerability_scanning/personal/

 

Reply #10 Top

Quoting Uvah, reply 9
Hang on: I clicked on the link and it took me to Secunia's website. Not to a porn site. I still have it up in a separate tab. I can show it to you if you like.
End of Uvah's quote

did you click or highlight and copy and Paste ??

 

****Removed****

Reply #11 Top

Quoting DisturbedComputer, reply 10
Quoting Uvah, reply 9Hang on: I clicked on the link and it took me to Secunia's website. Not to a porn site. I still have it up in a separate tab. I can show it to you if you like.

did you click or highlight and copy and Paste ??

 

cause ***Removed*** dose NOT take me to  

http://secunia.com/vulnerability_scanning/personal/   as the link for this in post 6 is not a click-able link for me

but ***Removed*** is 

 
End of DisturbedComputer's quote

 

I believe he may have accidentally inserted a "period" in the middle of his sentence and his browser might have auto-completed it for a link?

 

Reply #12 Top

***Removed***  is NOT the link. Do not click on it. The link is the http. Because huge dot at has the dot in it it shows as a LINK.I figured if you saw the secunia.com you'd do the same. Highlight ... copy/paste is what I should have said rather than clicked on the link. My bad.

Reply #13 Top

Guys... I believe this happened in honest error. inbloodofeden just didn't hit the space bar after the sentence... the site created the link.

Too bad it didn't lead to "How to make a zillion bucks by one mouse click".  ;)

 

Quoting the_Monk, reply 11
I believe he may have accidentally inserted a "period" in the middle of his sentence and his browser might have auto-completed it for a link?
End of the_Monk's quote

Correct.

Reply #14 Top

If anyone notices a link that is not suitable for this site then please use the 'report' function to notify a mod of it instead of quoting the link over and over again.

Reply #15 Top

My bad Let the kids click the link and see PORN

Reply #16 Top

Quoting Hankers, reply 14
If anyone notices a link that is not suitable for this site then please use the 'report' function to notify a mod of it instead of quoting the link over and over again.
End of Hankers's quote

 

I did I PM'ed  DrJBHL

 

Note MINE is NOT a link I Broke it ...

 

report' function ? where is this at  ?? 

Reply #17 Top

DC... everyone's heart was in the right place. Hankers is making the same point we always make regarding Piracy posts... not to repeat the links, and just report it.

You did pm me about it... up to there fine. Let's all just relax... and update!

*doc didn't get the pm until later because he was in the loo.... sorry... nature called.

Reply #18 Top

I did not 'click' the link. Read my post. Highlight, copy/paste. I worded it wrong. Okay? Okay.

Reply #19 Top

Hankers is making the same point we always make regarding Piracy posts... not to repeat the links, and just report it.
End of DrJBHL's quote

 

Quoting DisturbedComputer, reply 15
My bad Let the kids click the link and see PORN
End of DisturbedComputer's quote

 

Was not at Hankers

 

Reply #20 Top

At least they improved the update section, its nice to see that they are working on fixes and not only think about marketing IE currently

So yeah thats a pleasing statement and thanks to doc i can prepare myself early and do backups :P

Reply #21 Top

Quoting DisturbedComputer, reply 16
report' function ? where is this at ??
End of DisturbedComputer's quote

 

When you move your mouse pointer to the location below any comment you wish to report a 'report' button will appear as shown in the screen grab.

The forum moderator will receive an email with the link to the post and comment and will take any necessary appropriate action.

Reply #22 Top

*doc is forced to use the 'heavy artillery' to lighten the mood. Out comes trusty Ps and in the spirit of one of his other threads:

 

Reply #23 Top

Quoting Hankers, reply 21
When you move your mouse at the location below any comment you wish to report a 'report' button will appear as shown in the screen grab.
End of Hankers's quote

oh ok I have seen it just never seen it 

Reply #24 Top

I like you. You're silly. Seen it but never seen it. :rofl: :rofl: :rofl:

Back on topic. The only one I don't have is MS Office. What is GDI+?