Microsoft Patch Day: 1 Critical Bulletin on Tap

執筆者
Ryan Naraine
Ryan Naraine
Published: Nov 3, 2005
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Microsoft Corp.s security patch train will carry a light load this month.

Next Tuesday, the Redmond, Wash.-based software maker plans to issue a solitary bulletin to cover a “critical” flaw in the Windows operating system.

As is customary, the company is not releasing details on the vulnerability until Nov. 8.

The fact that the bulletin is rated “critical” suggests it covers a flaw that can be exploited to spread of an Internet worm without user action.

The update will be detectable using the MBSA (Microsoft Baseline Security Analyzer) and will accompany the monthly refresh of the malicious software removal tool, a free utility that lets Windows users zap known virus variants.

The news that only one patch is on tap means that a long list of known Windows vulnerabilities, some rated “high risk,” will remain unpatched.

/zimages/2/28571.gifClick hereto read more about the long list of unpatched Windows flaws.

eEye Digital Security, a security research outfit that regularly reports flaws to Microsoft, lists eight Windows flaws that have not yet been fixed.

Three of the eight are more than three months overdue. They affect users of two of the most widely deployed Microsoft products–the Internet Explorer browser and the Outlook e-mail program.

The company has also been tardy in addressing a publicly reported bug in the Microsoft Jet Database Engine.

That flaw, which was discovered by HexView Security Research and Assessment, affects fully patched systems with Microsoft Access 2003 and Microsoft Windows XP, including Service Pack 2.

The Jet DB engine vulnerability was reported to Microsoft more than seven months ago.

Malicious hackers have already exploited the flaw with a mail-borne Trojan that opens a back door on the compromised computer to allow a remote attacker unauthorized access.

/zimages/2/28571.gifCheck out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

Ryan Naraine

Ryan Naraine

Content Writer

Ryan Naraine is a ServerWatch, eSecurity Planet, and eWEEK contributor.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。