Woody Leonhard’s no-bull news, tips and help for Windows and Office
RSS icon Email icon Home icon
  • MS-DEFCON 4: Get Patched

    Posted on March 5th, 2010 at 07:15 woody 22 comments

    Microsoft just fixed the really bad February patch. MS10-015 / KB 977165, which I wrote about two weeks ago, had a nasty habit of clobbering Windows XP machines. According to a Microsoft Security Response Center blog, MS10-015 is now offered “with new logic that prevents the security update from being installed on systems if certain abnormal conditions exist.”

    In other words, if your WinXP PC is infected with the Alureon rootkit, MS10-015 won’t install itself, and you won’t be faced with an endless cycle of Blue Screens of Death.

    With that big problem out of the way, it’s now time to apply the February Black Tuesday patches. Get yourself all patched up, then make sure Automatic Updates is turned off. The two March patches will be out next week, and you don’t want Microsoft to zap you. Again.

    I’m moving us to MS-DEFCON 4: There are isolated problems with current patches, but they are well-known and documented here. Check this site to see if you’re affected and if things look OK, go ahead and patch.

  • MS-DEFCON 2: Black Tuesday patches are out

    Posted on February 10th, 2010 at 04:36 woody No comments

    And what a crop they are…

    As expected, Microsoft has just released 13 Security Bulletins which plug 26 separately identified security holes in Windows and Office. The list is mind-numbing.

    According to SANS Internet Storm Center, only one of the Security Bulletins has a known exploit. That Bulletin, MS10-015, covers a 17-year-old security hole in Windows that I described two weeks ago. I wouldn’t worry about it for the moment.

    The MS Security Research & Defense page has details about potential attack vectors, and speculation about how soon the bad guys will be able to take advantage of the security holes.

    Keep yer shirt on. Let’s see how things shake out. We remain at MS-DEFCON 2: Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don’t do it.

  • 13 Security Bulletins coming

    Posted on February 5th, 2010 at 03:37 woody No comments

    Hooooooo-boy….

    Microsoft just announced that it has 13 – count ‘em, a baker’s dozen – 13 Security Bulletins coming up on Tuesday.

    They affect both Windows and Office.

    Get yourself patched up right now, folks. Then make sure Automatic Updates is turned off, please. The PC you save may be your own…