Microsoft to Spackle Holes in Windows, Messenger, Visual Studio

Écrit par
Lisa Vaas
Lisa Vaas
Published: Sep 7, 2007
Updated: Feb 2, 2021
2 minute read
eWeek Le contenu et les recommandations de produits sont indépendants de la rédaction. Nous pouvons gagner de l'argent lorsque vous cliquez sur des liens vers nos partenaires. En savoir plus

Microsoft is planning to release five security bulletins on Septembers Patch Tuesday.

While only one—a vulnerability in Windows—is deemed critical, three of the advisories address vulnerabilities that can lead to system takeover: the Windows flaw, flaws in MSN Messenger and Windows Live Messenger, and holes in Visual Studio.

The IM client vulnerability in particular should be given priority, experts say.

“If the Windows Messenger vulnerability lends itself to a chat-based attack vector, then organizations and users of the ubiquitous Microsoft Messenger should pay attention, because this would be a prime candidate for spreading malware and viruses,” said Paul Zimski, senior director of market and product strategy for PatchLink, in a statement.

In its September 2007 advanced security bulletin notification, Microsoft said it also plans to release updates for SharePoint as well as for Windows Services for Unix and the subsystem for Unix-based applications. Outside of the one critical Windows advisory, the other four updates are all deemed important.

The eEye Zero-Day Tracker is currently listing three unpatched Microsoft vulnerabilities, but none of these are rated critical.

Click here to read more about why Microsoft shut down the independent AutoPatcher online download service.

While Sept. 11 may strike some as a Patch Lite Tuesday, experts warn that any vulnerability that could lead to remote code execution should be dealt with quickly.

“Although this month may be a reprieve from this years heavy patch releases, any vulnerability that lends itself to remote code execution should prompt IT administrators to identify which parts of their network are affected and to apply those patches first,” Zimski said.

Indeed, he said, finding systems vulnerable to the threats at hand will be the toughest part of dealing with this months patch deployments.

At any rate, whatever breathing room IT administrators get from having a less than onerous Patch Tuesday should be spent cleaning house, he said: updating network inventories, addressing backlogged vulnerabilities, classifying assets, prioritizing risk and measuring recent response times for patch implementation.

Advertisement

As it does every month, Microsoft will also be releasing an update to the Microsoft Windows Malicious Software Removal Tool. The company also plans to release one high-priority, non-security update on Microsoft Update but none released on Windows Update.

Check out eWEEK.coms Security Center for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEKs Security Watch blog.

Lisa Vaas

Lisa Vaas is News Editor/Operations for eWEEK.com and also serves as editor of the Database topic center. She has focused on customer relationship management technology, IT salaries and careers, effects of the H1-B visa on the technology workforce, wireless technology, security, and, most recently, databases and the technologies that touch upon them. Her articles have appeared in eWEEK's print edition, on eWEEK.com, and in the startup IT magazine PC Connection.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Propriété de TechnologyAdvice. © 2026 TechnologyAdvice. Tous droits réservés

Divulgation publicitaire : Certains des produits qui apparaissent sur ce site proviennent d'entreprises dont TechnologyAdvice reçoit une compensation. Cette compensation peut influencer la façon dont les produits apparaissent sur ce site, notamment l'ordre dans lequel ils apparaissent. TechnologyAdvice n'inclut pas toutes les entreprises ou tous les types de produits disponibles sur le marché.