Welcome | Sign In
TechNewsWorld.com
Security

Microsoft to Take a Pass on Patch Tuesday

Print Version
E-Mail Article
Reprints
Microsoft to Take a Pass on Patch Tuesday

Microsoft isn't talking about why it has decided to omit its monthly distribution of security patches. There are several serious problems awaiting fixes, including five zero-day vulnerabilities. The company might be holding off in order to give IT staff a break as they prepare for the early switch to daylight saving time, suggested Yankee Group analyst Laura DiDio.


Tech Industry Paper - Finding Strength Through Customer Service
Poised to capitalize on an upturn in the economy, technology companies are focused on retention & service. This paper, from Convergys, provides the latest research on customer experience for B2B & B2C technology customers. Learn more.

Microsoft (Nasdaq: MSFT) plans to skip its monthly round of security patches scheduled for release next Tuesday, despite at least five zero-day vulnerabilities waiting to be fixed.

Redmond is working on patches for known vulnerabilities in Internet Explorer 7, Office 2007's Publisher 2007 and Windows Vista OS, but is not ready to release any fix at the moment, according to the company.

In its monthly advance notification bulletin posted Friday, the company stated, "No new Microsoft Security Bulletins will be released on March 13, 2007."

The second Tuesday of each month is Microsoft's scheduled patch release day.

Breaking the Cycle

The rare break from the regular patch cycle could be designed to give weary IT managers a breather. Last month, Microsoft released 12 updates that fixed 20 vulnerabilities, and in January, the software giant issued four security bulletins and patched 10 bugs.

"Microsoft doesn't want to slam IT managers," Laura DiDio, an analyst with the Yankee Group, told TechNewsWorld. That is one of the reasons the company moved from weekly patches to monthly patches a few years ago, she noted. "They don't want IT managers to be overwhelmed."

In addition to a busy beginning of March, many IT staffers in the United States have become occupied with the switch to daylight saving time, which Congress moved forward three weeks this year in order to save energy. Many computer systems don't have the change programmed in and require patching.

However, DiDio acknowledged that this is all conjecture, because Microsoft is remaining mum for now.

"Everyone would feel better about this if they said there are no patches because we have no security problems to fix," said DiDio, "but we know that isn't the case."

The move marks the first time in 18 months that Microsoft has not issued at least one security update in a scheduled patch cycle. Since January 2003, only three months have been sans security fixes, she observed.

Keeping Busy

Although Redmond isn't releasing security fixes on Tuesday, it will keep busy by moving ahead with an updated release of its Windows Malicious Software Removal Tool. The program detects and removes common malicious code placed on computers and is pushed out monthly.

"Microsoft continues to investigate potential and existing vulnerabilities in an effort to help protect our customers," the company said in a statement.

There are five known zero-day holes in Microsoft products that are still out there that can be exploited by hackers, according to eEye Digital Security.

Nine bugs are still listed on the SANS Institute's Internet Storm Center's most recent "missing Microsoft patches" chart.


Print Version E-Mail Article Reprints More by Tim Gray


Related News Alerts

Microsoft Activate Alert | Search Archives

More by Tim Gray

Blockbuster Lowers Subscriptions Rates
June 13, 2007
Blockbuster will now offer a new plan allowing customers to place online orders to rent three movies at a time for $16.99, a dollar less than its previous top-tiered offering, called Total Access. The movies are mailed to the customer. Blockbuster is losing money on the online business but says it will be profitable next year as orders rise.
Toshiba Slashes HD DVD Sales Targets
June 12, 2007
Toshiba now expects to sell 44 percent fewer HD DVD players than forecast this year. The slump comes at a critical time for the company, as the market still has not shown which high definition disc player format will dominate. Blu-ray Disc technology, rival of the HD DVD format, already has a foothold in 170 major companies.
Jobs: We Also Make Computers
June 12, 2007
Apple provided at its annual developer conference a peek at some of the 300 new features of "Leopard," the company's latest operating system, which is slated for October release. The computer maker will also make its Safari Web browser available for users of Microsoft's Windows operating system.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network