No Windows Patch on Patch Tuesday as Microsoft Pulls the Patch   - 1,550 Views,

Summary: Microsoft Patch Tuesday is the second Tuesday of each month, and the day when, traditionally, Microsoft has released patches and other security updates for the Windows operating system. But while a patch was promised for this Patch Tuesday, none materialized. Here's why.
  

Previous Article « Paris Hilton’s Teen DFNCTS Hacker Pleads Guilty - Member of Defonic Crew Team Screen Name Club
Read Next Article » Microsoft Issues Lawsuit Challenge to Google: Settle

No Windows Patch on Patch Tuesday as Microsoft Pulls the Patch        Follow Anne on Twitter     Friend Anne on Facebook

There is no patch from Microsoft today, yes, it’s true. While as sure as Wednesday night was Prince Spaghetti Night, so the second Tuesday of the month is Microsoft Patch Day, the software giant has pulled the patch it was planning to release today.

Indeed, as recently as last Thursday, Mike Reavey, a lead Security Program Manager with Microsoft, posted to the Microsoft Security Response Center (MSRC) blog that “This coming Tuesday, we’re planning to release one security bulletin, and its (sic) in Windows. The maximum severity rating for this is Critical, so please update systems as soon as possible. We don’t expect this update to cause a reboot and it can be deployed and detected with MBSA, Microsoft Update, and WSUS. Also, we’re going to release an updated version of the Malicious Software Removal Tool.”

However, later in the week Reavey posted that “we’ve had a little change in plans for next week and wanted to make you all aware of it. This afternoon we revised the information in the Advance Notification to reflect a change for next week’s release. Microsoft will not be issuing any new security updates on September 13th as part of the September monthly bulletin release cycle.”

Why did Microsoft pull the patch? Especially with it being rated “Critical”? According to Reavey, they found a quality issue with the patch, and so decided to delay its release.

Explained Reavey on the blog today, “While the decision to not ship the security update was a difficult one, it was encouraging to see that several customers, security researchers and even the press felt it was the right decision.”

Apparently not all customers and press feel that it was the right decision. Security Focus quotes several industry participants as being quite concerned about the turn of events.

“There’s knowledge of a flaw and, because (Microsoft) can’t meet the deadline of the next few days, they’re going to delay it a month. So from a security point of view, we have a hole that is known but not patched,” said one member of a security mailing list. “In my scheduled time with limited resources, I allocate a certain amount of time to patching systems. I may not want to do an out-of-band or ad-hoc deployment of a critical patch that is not related to a virus outbreak or worm. I understand the day may arise where 0-day worms are created. However, until such time I am going to stick to my schedule,” said another.

“Almost every other major software company is still able to produce a patch in a short time, but Microsoft takes six months or more,” observed Marc Maiffret of eEye Digital Security.

Still, as Bruce Schneier of Counterpane Internet Security points out, “This is the Catch-22 for software vendors. A badly written, badly tested patch would be worse than the attack. Microsoft has to get it right. The problem is that they also have to get it fast.”

Was this information helpful? If so, please leave us a review!

SHARE:
No Windows Patch on Patch Tuesday as Microsoft Pulls the Patch
SOCIAL:        Friend Anne on Facebook        Follow Anne on Twitter        Twitter Explained in Plain English
SEARCH:
       

Leave a Comment

Previous Article « Paris Hilton’s Teen DFNCTS Hacker Pleads Guilty - Member of Defonic Crew Team Screen Name Club
Read Next Article » Microsoft Issues Lawsuit Challenge to Google: Settle

Read more:

»  Microsoft WMF Patch for Windows Metafile (WMF) Issue Released Early - Get It Now!

»  Emergency Windows Patch Issued by Microsoft - Get It Now!

»  Windows ActiveX Flaw Still Active After Patch

»  Screwed If You Do, Screwed If You Don’t - Windows Update Causes Crashes (KB891711)

For additional similar stories check out our archives on Security, Windows

NOTE: We never, ever, ever will recommend any product or service on this site that we have not regularly used ourselves and do not wholeheartedly believe in. That said, in some cases after being very pleased with a product or service, we may enter into a relationship with the provider of that product or service such that if someone purchases that product or service based on our recommendation, we may get a small payment. Such payments go towards the upkeep of the Internet Patrol.

 

No Comments »

No comments yet.

RSS feed for comments on this post.

Leave a comment

Warning! All comments which contain URLs and are clearly just spam to generate a link back to the URL will be deleted on sight. Don't bother wasting your time!

If you are going to include a URL in your comment,
please keep it under 25 characters in length,
or use TinyURL to shorten it before including it in your comment.

Line and paragraph breaks are automatic, your email address is never displayed.

(required)

(required)


 
 This article first appeared on 9/13/2005
The Internet Patrol
Patrolling the Internet for You!