Microsoft rushes out fix

Patch out not a moment too soon

Written by Madeline Bennett

Microsoft yielded to intense pressure from customers in January and rolled out an emergency patch to fix a serious Windows Metafile (WMF) flaw. The move followed the launch of unofficial fixes, which some security experts had advised firms to deploy.

The software giant was due to release the fix on Tuesday 10 January as part of its monthly patch bundle. However, earlier in the month it gave in to customer pressure to release a fix early.

Experts welcomed the decision. “The patch was obviously deemed critical enough to break the traditional patch cycle – a benefit to all Microsoft users,” said Alan Bentley, UK managing director at PatchLink.

But the length of time taken to roll out patches within enterprises could let hackers continue exploiting the bug for some time. “Average numbers from last year were around 30 days to get a patch fully deployed across a corporate network,” Bentley said.

Meanwhile, the situation highlighted a dilemma for firms on where to look for protection, as unofficial fixes for the bug had already been released. One unofficial fix, released by software developer Ilfak Guilfanov, was endorsed by organisations including the Internet Storm Center (ISC).

Andy Kellett of analyst Butler Group said his firm usually advises against applying unofficial patches as they could worsen problems.

“But this particular vulnerability was serious enough to be worried about and the [Guilfanov] patch was authenticated by some strong authorities,” he added.

Tags:

reader comments

related articles

Microsoft

Microsoft readies eight October patches

Security bulletin reveals one patch rated 'critical' 07 Oct 2005

 

Microsoft slammed for 'confusing' open source study

Novell picks holes in 'independent' report 21 Nov 2005

Worm emerges for latest Microsoft flaw

Attacks reported on recently-patched Windows hole 05 Nov 2008

OpenOffice users urged to apply security fixes

Patches address a pair of critical flaws 31 Oct 2008

Major DNS flaw revealed

Experts sound alarms over early disclosure 23 Jul 2008

related whitepapers

today's top stories

IT's stock is soaring at the LSE

London Stock Exchange IT chief David Lester explains to Angelica Mari how the integration of Borsa Italiana is keeping his team busy, despite the worsening economy 20 Nov 2008

Cutting-edge IT delivers the goods

Chief technology officer Jay Bregman explains how constant innovation is part and parcel of his strategy for delivering competitive advantage at eCourier 20 Nov 2008

Computing podcast: Europol's data sharing woes; credit card protection at Cotton Traders

The pan-European fight against organised crime is undermined by lax data sharing arrangements; and Cotton Traders enhances its credit card protection 20 Nov 2008

Keeping IT on track

Catherine Doran, winner of Computing’s IT Leader of the Year award, tells Angelica Mari of her determination to drive on with technology-led transformation at Network Rail despite uncertainty over funding 19 Nov 2008

Examining the IT skills challenge

Watch a BCS roundtable debate on the issues affecting IT professionals - the last of a four-part series 17 Nov 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Has the state of the economy forced to re-evaluate your IT purchasing options?

Has the state of the economy forced to re-evaluate your IT purchasing options?

Are you re-thinking your IT spending?

Previous poll results

Latest audio and video articles

Video

The definitive guide to converged communications

Five key trends and five best practice tips to help you improve your corporate communications 20 Nov 2008

PodcastAudio

Computing podcast: Europol's data sharing woes; credit card protection at Cotton Traders

The pan-European fight against organised crime is undermined by lax data sharing arrangements; and Cotton Traders enhances its credit card protection 20 Nov 2008

Latest in-depth articles

Dave BaileyComment

Clouds darken outlook for Vista's successor

Windows 7 looks like being an improvement on Vista, but economic and environmental concerns may mean few enterprises will rush to adopt it 20 Nov 2008

Soca unitAnalysis

EU police in the dock over data sharing

Poor integration and lax practices are jeopardising EU efforts to fight international crime 20 Nov 2008

Advertisement

Primary Navigation