Microsoft Plans Critical Windows Security Patches

執筆者
Brian Prince
Brian Prince
Published: Jul 6, 2013
Updated: Feb 2, 2021
3 minute read
Microsoft Plans Critical Windows Security Patches
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Microsoft is planning to patch several critical vulnerabilities next week for Patch Tuesday, including a Windows vulnerability that recently sparked a debate regarding responsible disclosure.

All totaled, the company will be releasing seven security bulletins July 9, including six that are rated “critical” and affect Internet Explorer, Windows, the .NET Framework, Silverlight and GDI+.

“IT admins may take [July 4] off to enjoy some fireworks, but they’ll be very busy next week patching their systems,” said Paul Henry, security and forensic analyst at Lumension.

The six critical bulletins this month brings the total for the year to 22, which Henry called a fairly high number considering Microsoft only released 34 critical bulletins during all of last year.

“All six of the critical bulletins this month are remote code execution vulnerabilities, which I find concerning,” he added. “Since these types of vulnerabilities give attackers access to your machine without needing physical access or sometimes even a password, it’s definitely a cause for concern.”

Among the vulnerabilities scheduled to be fixed is CVE-2013-3660, a vulnerability in the Windows kernel that, if exploited, could be used by an attacker to execute code. The bug became the center of a dustup between Microsoft and security researcher Tavis Ormandy of Google when Ormandy posted details of the bug to the Full Disclosure mailing list in May. Later, he published a working exploit for the vulnerability as well.

In the midst of the fallout, Google recommended that security researchers give vendors only seven days to release updates or mitigations for zero-day vulnerabilities under attack in the wild. In the past, the firm had advocated for 60 days.

“Seven days is an aggressive timeline and may be too short for some vendors to update their products, but it should be enough time to publish advice about possible mitigations, such as temporarily disabling a service, restricting access, or contacting the vendor for more information,” Google security engineers Chris Evans and Drew Hintz wrote in a joint blog post in May. “As a result, after 7 days have elapsed without a patch or advisory, we will support researchers making details available so that users can take steps to protect themselves. By holding ourselves to the same standard, we hope to improve both the state of web security and the coordination of vulnerability management.”

Advertisement

Microsoft has not indicated any change in policy in regard to the issue and has said the company believes researchers should work privately with vendors to coordinate disclosure after patches and mitigations are made available.

In addition to the critical bulletins, there will also be a bulletin rated “Important” that addresses an issue in Microsoft Security Software.

“While it’s less worrisome than the other bulletins because it’s ranked Important, it is still concerning in that it’s directly impacting the security system for the machine,” Henry said. “Windows Defender is also free software, making it very widely used. If an attacker got in as a low-rights user and then used this bulletin to up their privilege level to admin, the impact would in fact be critical. I would rank this high in the priority list for that reason.”

Brian Prince

Brian Prince

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。