Next week will be a busy one for IT administrators. Microsoft plans to release six patches for December’s Patch Tuesday — three rated critical and three important. The patches will address 12 vulnerabilities in Windows, Internet Explorer, and Microsoft Office.
“To help customers plan for their deployment of these updates, I want to specifically call out that they touch all supported versions of Windows and IE,” said Jerry Bryant of the Microsoft Security Response Center. “On the Office side, the bulletins impact Project, Word and Works 8.5. All of the updates for Windows will require a restart, so please plan accordingly.”
Patching the IE Flaw
At the top of the list for IT administrators — and at the top of Microsoft’s deployment list — is a vulnerability in IE 6 and 7 that could lead to remote code execution. Although Microsoft is not aware of any active attacks that seek to exploit this vulnerability, it is severe enough that the company considered releasing an out-of-band patch on Nov. 23.
The IE fix is part of Bulletin 4, which will have the broadest impact because it will affect all user machines across an entire organization, according to Don Leatham, Lumension senior director of solutions and strategy.
“It is critical across Windows 7, Vista and XP; requires a restart; and impacts all versions of Internet Explorer 6, 7 and 8,” Leatham said. “We suggest that IT departments be prepared to quickly assess and patch all end-user machines throughout their organization.”
Disrupting Windows Server
Bryant said the other critical update affecting Windows is in Bulletin 1. Although this bulletin has a critical severity rating, he said, the lower risk will drop the deployment priority down a little. But security researchers said the importance shouldn’t be underestimated for Windows Server 2008 users.
“If IT teams have Windows Server 2008 deployed…