Microsoft to Patch WMF Exploit Early
Chran writes "Microsoft has just announced that they will release a security update for the .WMF-exploit today at 2pm ET, instead of Tuesday, as originally planned.
Microsoft writes: "Microsoft originally planned to release the update on Tuesday, January 10, 2006 as part of its regular monthly release of security bulletins, once testing for quality and application compatibility was complete. However, testing has been completed earlier than anticipated and the update is ready for release. In addition, Microsoft is releasing the update early in response to strong customer sentiment that the release should be made available as soon as possible."
Microsoft is releasing the update early in response to strong customer sentiment that the release should be made available as soon as possible.
It would have been nicer if they make patches available as soon as possible with or without strong customer sentiment.
Virtual Betting on Facebook for non-geeks.
...only 10 days too late...
---
tis is not a FP
Maybe it is just me, but 8 days for a tested patch does not seem that long. However it was a 0 day which made this exploit special.
"It appeared that there had even been demonstrations to thank Big Brother for raising the chocolate ration to twenty grammes a week. And only yesterday, he reflected, it had been announced that the ration was to be reduced to twenty grammes a week. "
Damned if they send out patches as they're made (too many, too confusing) and damned if they wait 'til Patch Tuesday (negligent, inconsiderate).
We can't have it both ways, and neither should they. I say send out patches as they're made and let the sysadmins be responsible for whether they can keep up or not. It may be difficult to admin many machines that have to be patched but I'd rather have fixes available ASAP and put the burden on IT to apply them.
Yeah, there are patches that will break stuff and ample testing should be done anyway...but does rolling them all into a Patch Tuesday really change that fact? Probably not.
With this sentiment, we can put more pressure on Patch Tuesday for what it really is -- a Trustworthy Computing PR stunt in which the number of fixes and vulnerabilities seems to be lower (since we're only patching once a month...maybe).
All that said, kudos to MS for reacting...but unkudos for taking this long...and major unkudos for being naive about the WMF design to begin with.
Well the funny thing is that this exploit only affects Internet Explorer as well. So basically what they are saying is
They aren't "saying" anything. The Windows Update web app, as a requirement of the fact that it uses ActiveX, requires Internet Explorer. Nonetheless, not only is the patch rolling out right now via auto-updates, you can also download it directly.
In any case, even though I use Firefox and Opera for my day to day browsing, I really don't feel that threatened firing up Internet Explore for the purpose of connecting to Microsoft.
Telling everyone that they are going to wait till Tuesday to patch the problem, then releasing a patch 5 days earlier might actually be quite a neat trick.
I'm sure a lot of people out there who were planning to taking advantage of this problem have been thinking that they have till Tuesday to write a really good exploit, and therefore not hurrying too much.
Now Microsoft come along and patch it early.
I don't know about anyone else but I was expecting Monday do be a day from hell...
They just blocked the execution of the vulnerable function. This to me a mitigation method not a patch. Think of it as, there is a vulnerability in mod_rewrite within apache, and a third party "patch", just disables it, to secure apache.
Translation: "Our ass needed covering even earlier than anticipated."
Tag lost or not installed.
No, they're just companies that can't spend half a million dollars upgrading hardware and software just to run the latest whizz-bang eye candy from microsoft, when what they have works just fine.
Over 40% of our customers are NT4 shops. Some of them are *big*.