• Time to get caught up on your patches

    I’m giving the go-ahead, and recommending that you apply all outstanding Windows XP and Vista patches, except the Core 2 Duo microcode patch, KB KB 933576. You should also avoid the .NET Framework megapatch, MS07-040 / KB 931212, unless you have a program that specifically requires it.

    The rest of the September and October patches for both Windows XP and Windows Vista appear to be relatively benign (several have been re-patched) and at this point should do more good than harm. In particular, the Vista “compatibility, reliability, and stability” patches have stabilized significantly.

    I also recommend that you install Office 2003 Service Pack 3, plus any odd patches offered for other versions of Office. The initial problems appear to have worked themselves out. Realize that SP3 changes the way several Office features work, and clobbers others, but the zapped features really can make your life more difficult. There’s a long list of changes in the “Known Issues” section of Knowledge Base article 923618.

    Finally, it’s vitally important that you patch Firefox, QuickTime and Java. All three should be offered to you automatically. Go ahead and accept the offer to patch.

    Once you’ve caught up on your patching, make doubly sure that you have Automatic Updates turned off. (Note that installing Windows Live Payola OneCare turns on automatic updates.) November’s Black Tuesday isn’t far away.

    We’re at MS-DEFCON 4: There are isolated problems with current patches, but they are well-known and documented here. Check this site to see if you’re affected and if things look OK, go ahead and patch.