Newsletter Archives
-
MS-DEFCON 4: Get patched
The January crop of Microsoft Security Bulletins have been through the wringer and seem to be stable at this point.
MS12-005 unexpectedly changed the behavior of Office applications when opening an embedded OLE package, but it’s just an inconvenience, not a killer. MS12-012 can cause problems with web browsing, but only if you’ve changed a very obscure setting that involves the default encoder for ASP.NET WebForms.
All in all, it isn’t enough to hold you back. Get all of your Microsoft patches applied now, and make sure Automatic Update is turned off.
-
MS-DEFCON 2: New patches are out – hold off
The January 2012 Security Bulletins are out, and there aren’t any screaming “install me” at the moment.
The biggest hole is covered by MS12-004, the Windows Media Player patch. There are no known exploits at this point.
Make sure you’re locked down, and let’s see how this month’s crop goes.
I’m moving us up to MS-DEFCON 2: Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don’t do it.