Microsoft to Patch WMF Exploit Early
Chran writes "Microsoft has just announced that they will release a security update for the .WMF-exploit today at 2pm ET, instead of Tuesday, as originally planned.
Microsoft writes: "Microsoft originally planned to release the update on Tuesday, January 10, 2006 as part of its regular monthly release of security bulletins, once testing for quality and application compatibility was complete. However, testing has been completed earlier than anticipated and the update is ready for release. In addition, Microsoft is releasing the update early in response to strong customer sentiment that the release should be made available as soon as possible."
I think that some corporate users (especially) are quite thankful for patch Tuesdays; especially those that have been bitten by some compatibility issue previously and can't just run autoupdate of all desktops at night, but rather want to roll it out manually.
Again, this is not the case here, this exploit was discovered in the wild and it's spreading right now.
The exploit writers have had the exploit ready for quite a while now.
While MS was 'testing' everyone has been installing 'fixes' from other sites..
Even IF their patch was not 100% it wouldn't really have mattered in this case.
There was a gaping security hole in their OS and they still needed 12 days to come up with a fix!
For such a large company whose software is being used by *millions* of people worldwide and 7 billion a quarter profit, they've sure taken their sweet time!
Why don't they take some 0.01 procent of that 7 billion and test/release it sooner?
They had it ready, if by ready you mean a version had been compiled and 'tested' once on the developer's machine.
Trust me, right now in Redmond there's a whole team of Quality Assurance Engineers who are looking at their test plans, scratching their heads, and once again calling into question the actual value of their work, given that some manager can arbitrarily decide when it's time to rush a release regardless of what the schedule said or what the impact of a patch was or which cases remain un-tested. That, and they're really, really tired after pulling a couple of all-nighters.
Have fun testing that patch.
Posted by CmdrTaco on Thursday January 05, @12:56PM (3:56PM EST)
.WMF-exploit today at 2pm EST
Chran writes "Microsoft has just announced that they will release a security update for the
talk about releasing the news late.. the patch was already out by the time slashdot had the "news" that microsoft would be releasing the patch.