Microsoft on Thursday warned IT professionals about the heavy load of patches coming their way. On April 13, the next Patch Tuesday will see nearly a dozen patches to follow an unusually light release in March.
Specifically, Microsoft is releasing a total of 11 patches in April to address 25 vulnerabilities. Five of the patches are critical and involve remote code execution, and four require a restart. The five critical bulletins affect all versions of Windows software that are widely being used and could therefore cause an interruption in services affecting work flow and productivity levels.
Patches Across the Board
“Overall, April’s Patch Tuesday bulletin will address at least two critical vulnerabilities for every popular Microsoft platform in use today, so the impact will be widespread regardless of what operating systems companies are currently running,” said Don Leatham, director of solutions and strategy at Lumension.
“This means IT departments will have to address and patch almost every machine in the organization. They should be prepared this month and plan ahead as to how they are going to test and then deploy these patches with minimal interruptions to employee productivity levels.”
The VBScript Flaw
Noteworthy is the fact that there are two known public security advisories that Microsoft will address with these patches: 981169 and 97754.
Microsoft is addressing a vulnerability in VBScript that is exposed on supported versions of Microsoft Windows 2000, Windows XP, and Windows Server 2003 through the use of Internet Explorer. Microsoft started investigating the issue on March 1. The results: The vulnerability cannot be exploited on Windows 7, Windows Server 2008 R2, Windows Vista, or Windows Server 2008. The main impact of the vulnerability is remote code execution.
The vulnerability exists in the way that VBScript interacts with Windows help files when using Internet Explorer. If a malicious web site displayed a specially…