Next Patch Tuesday fixes critical holes in Internet Explorer and Windows Server
Summary
For Patch Tuesday on 9 August 2011, Microsoft announced 13 bulletins intended to close 22 holes. Among them were critical holes in all versions of Internet Explorer and in most editions of Windows Server, both exploitable remotely for code execution. Further updates concerned Windows, Office 2003 to 2010, .NET 3.5 and Visual Studio 2005.
Ideas
- A fixed monthly patch day makes updates predictable for administrators.
- The advance notice allows maintenance windows to be prepared.
- Critical holes affected both client and server systems.
Insights
- Predictable patch cycles help defenders but also show attackers when holes will become public.
- A single patch day bundles many risks that have to be prioritised together.
Facts
- The critical holes allowed remote code execution.
References
Critique
- As an advance notice, the report contains no details on attack paths or workarounds.
Recommendations
- Schedule fixed maintenance windows shortly after the patch days of your most important vendors.
- Prioritise updates for servers reachable from the network and for browsers.
Links to the original source and the Web Archive open in a new tab.