Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity
    • Networking

    Some Patching Up Is in Order

    Written by

    Dennis Fisher
    Published January 16, 2006
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Its been a long time since the security community had a full-fledged Microsoft patch controversy to sink its collective teeth into, but the new year was just a couple of days old when the first opportunity presented itself in the form of the Windows Metafile vulnerability.

      The flaw, which allows attackers to take control of remote systems, affects essentially every version of Windows that might possibly be running on a machine somewhere. Within days of the vulnerability becoming public at the end of last month, there were thousands of individual sites distributing exploit code for the hole.

      Its the kind of vulnerability that typically would merit a critical rating from Microsoft, which would translate into a long night and lots of downtime for enterprise IT shops as they scramble to patch thousands of systems.

      /zimages/1/28571.gifClick here to read more about Microsofts “emergency” patch of a WMF flaw.

      The only problem is that Microsoft initially didnt think it was a big deal. Or, at least not a big-enough deal to break out of its monthly patch cycle and issue an emergency fix. Company officials were busy telling anyone who would listen in the last couple of weeks that, yes, the WMF flaw was a concern, and they would be happy to release a patch for it on Jan. 10, the next regularly scheduled patch day.

      But, in the meantime, security researchers, anti-virus companies and security vendors began releasing their own fixes for the WMF problem, something that is not altogether unheard of.

      What is unusual, however, is that IT managers and security administrators were so concerned with this flaw that some of them were actually installing patches written by people they had never heard of.

      This is not the optimum way to run an IT shop in a major enterprise. But thats hardly the fault of the IT staffs; theyre just doing their best to protect their networks in the absence of any help from Microsoft.

      Lets get one thing out of the way upfront: No one in the industry is doing a better job handling the whole vulnerability/patching cycle than Microsoft. In fact, no other vendor is even a close second.

      /zimages/1/28571.gifRead more here about a critical Windows patch that sought to fight takeover attacks.

      The Microsoft Security Response Center is the class of the industry and should be used as a model by other vendors (Sun, Oracle, Im looking your way) for how to set up a comprehensive process for working with researchers, developing and testing a patch, and then disseminating it in the most efficient way possible.

      Let us not forget that it was only a few short years ago that Microsoft patches would arrive out of the blue with no warning, sometimes five or six at a time. This model forced administrators to drop everything and start testing and deploying patches as soon as they could.

      Now, Microsoft not only releases fixes on a regular monthly basis, but it also notifies customers ahead of the release date how many patches are coming and how important they are.

      But—and this is a very big but—Microsoft seems to have become too locked in to its monthly release cycle. The companys insistence on sticking to its schedule at all costs puts customers at risk and, even worse for Microsoft, makes those same customers think that the company has reverted to its old habit of patching when it was good and ready.

      In the case of the WMF flaw, Microsoft eventually released the patch five days before the monthly patch day, but only after what company officials termed “intense” pressure from customers.

      Roughly translated, that likely means there were a lot of calls emanating from the 212 and 202 area codes coming into Redmond, with large financial and government customers wondering why their security teams were scrambling to implement workarounds they found on newsgroups or patches from Ukrainian hackers when theyre paying Microsoft wheelbarrows full of money every year for legitimate updates.

      The WMF episode is much more likely to be the exception rather than the rule going forward, but if Microsoft wants to continue to claim the moral high ground in the security debate, it cant have these kinds of slip-ups.

      News Editor Dennis Fisher can be reached at [email protected].

      /zimages/1/28571.gifCheck out eWEEK.coms for Microsoft and Windows news, views and analysis.

      Dennis Fisher
      Dennis Fisher

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×