Woody Leonhard’s no-bull news, tips and help for Windows and Office
RSS icon Email icon Home icon
  • MS-DEFCON 4: Get patched now

    Posted on August 5th, 2010 at 10:36 woody 22 comments

    The July Black Tuesday patches have come and gone, and they’re not too bad.

    Now’s a good time to get patched up. I recommend that you apply all outstanding Microsoft patches, then make sure you have Automatic Update turned off in anticipation of next week’s onslaught.

    Those of you with Windows XP Service Pack 2 or Windows 2000, or if you use ESET NOD32 antivirus, please note the blog entry below. You’ve got some interesting times ahead.

    I’m moving us down to MS-DEFCON 4: There are isolated problems with current patches, but they are well-known and documented here. Check this site to see if you’re affected and if things look OK, go ahead and patch.

    UPDATE: Sorry, I should’ve made it more clear. Yes, I’m recommending that you go ahead, throw up your hands and give in to the offered .NET patches. I don’t think there’s any chance MS is going to fix any of them from this point – so patch ‘em and brace yourself for the next round.

  • MS-DEFCON 2: Get patched, then shut down Auto updates – fix for the Help 0day coming

    Posted on July 12th, 2010 at 07:48 woody 14 comments

    Microsoft has announced that it will deliver four security bulletins on Tuesday July 13.

    Three of them don’t appear to be terribly interesting, but one of them must be. Quoth Microsoft:

    We are also closing Security Advisory 2219475 (Vulnerability in Windows Help and Support Center Could Allow Remote Code Execution) with a comprehensive update that addresses the issue currently under attack.

    Looks like MS is finally going to plug the security hole I talked about a week ago. I’m still not convinced it’s a Big Deal, but it’ll be nice to get it fixed.

    Get all of the MS patches applied, except the .NET patches, then make sure you have Automatic Updates turned off. Let’s see what Tuesday will bring.