<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Patch Tuesday on Omid Farhang</title><link>https://omid.dev/tags/patch-tuesday/</link><description>Recent content in Patch Tuesday on Omid Farhang</description><image><title>Omid Farhang</title><url>https://omid.dev/images/bio-photo-150x150.jpg</url><link>https://omid.dev/images/bio-photo-150x150.jpg</link></image><generator>Hugo -- 0.163.3</generator><language>en-US</language><copyright>2026 Omid Farhang | All rights reserved.</copyright><lastBuildDate>Wed, 24 Apr 2013 12:56:13 +0000</lastBuildDate><atom:link href="https://omid.dev/tags/patch-tuesday/index.xml" rel="self" type="application/rss+xml"/><atom:link href="https://pubsubhubbub.appspot.com/" rel="hub"/><item><title>Microsoft patches the security update 2823324</title><link>https://omid.dev/2013/04/24/microsoft-patches-the-security-update-2823324/</link><pubDate>Wed, 24 Apr 2013 12:56:13 +0000</pubDate><guid>https://omid.dev/2013/04/24/microsoft-patches-the-security-update-2823324/</guid><description>&lt;p&gt;&lt;a href="https://omid.dev/images/2013/04/windows-update3.jpg"&gt;&lt;img loading="lazy" src="https://omid.dev/images/2013/04/windows-update3.jpg" alt="windows update[3]" /&gt;
&lt;/a&gt;Microsoft is making another attempt to close the privilege elevation hole in the NTFS filesystem&amp;rsquo;s kernel driver for Windows 7 and Server 2008, including R2. The new patch, &lt;a href="http://support.microsoft.com/kb/2840149"&gt;2840149&lt;/a&gt;, supersedes security update 2823324, which Microsoft released on its &lt;a href="http://www.h-online.com/news/item/Springtime-for-patches-Microsoft-9-Adobe-3-1838189.html" title="Springtime for patches: Microsoft 9 - Adobe 3 – 10 April 2013, 09:16"&gt;April Patch Tuesday&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;However, shortly after releasing it, the software giant had to &lt;a href="http://www.h-online.com/news/item/Microsoft-pulls-security-update-for-Windows-and-Windows-Server-1840815.html" title="Microsoft pulls security update for Windows and Windows Server – 12 April 2013, 10:52"&gt;recall&lt;/a&gt; the first update because it caused problems with various third-party programs; it crippled computers and triggered error messages. Kaspersky&amp;rsquo;s anti-virus programs also started acting up once the update was installed, erroneously assuming that they no longer had a valid licence and discontinuing operation. When re-releasing the update, Microsoft didn&amp;rsquo;t clarify whether this was the reason for the system malfunctioning.&lt;/p&gt;</description></item><item><title>Microsoft to plug holes in Windows Defender in Patch Tuesday</title><link>https://omid.dev/2013/04/05/microsoft-to-plug-holes-in-windows-defender-in-patch-tuesday/</link><pubDate>Fri, 05 Apr 2013 20:18:00 +0000</pubDate><guid>https://omid.dev/2013/04/05/microsoft-to-plug-holes-in-windows-defender-in-patch-tuesday/</guid><description>&lt;p&gt;&lt;a href="https://omid.dev/images/2013/04/windows-update3.jpg"&gt;&lt;img loading="lazy" src="https://omid.dev/images/2013/04/windows-update3.jpg" alt="windows update[3]" /&gt;
&lt;/a&gt;Microsoft&amp;rsquo;s Patch Tuesday on 9 April will be an important spring cleaning day; the company plans to implement &lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-apr"&gt;nine security bulletins&lt;/a&gt;. One of the bulletins deals with vulnerabilities in Windows Defender for Windows 8 and RT; the hole is rated as important and can be exploited to achieve elevated privileges.&lt;/p&gt;
&lt;p&gt;The headline bulletins will be the two critical security holes, one of which affects all versions of Windows and Windows Server, and another critical vulnerability which can be found in all versions of Internet Explorer. Whether the Internet Explorer fix will be addressing the IE vulnerability revealed at the recent Pwn2Own contest is unclear though. Both critical holes allow for remote code execution.&lt;/p&gt;</description></item><item><title>Microsoft's Patch Tuesday will close a critical Windows vulnerability</title><link>https://omid.dev/2012/03/10/microsofts-patch-tuesday-will-close-a-critical-windows-vulnerability/</link><pubDate>Sat, 10 Mar 2012 16:22:00 +0000</pubDate><guid>https://omid.dev/2012/03/10/microsofts-patch-tuesday-will-close-a-critical-windows-vulnerability/</guid><description>&lt;p&gt;&lt;strong&gt;&lt;img loading="lazy" src="http://lh6.ggpht.com/-mems2pQ0gkQ/T1t4yMcmaPI/AAAAAAAAFIE/0KzxeoLwP7A/s1600-h/windows%252520update%25255B4%25255D.jpg" alt="windows update" /&gt;
The H-Security:&lt;/strong&gt; Next week&amp;rsquo;s Patch Tuesday sees Microsoft planning to publish a total of &lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-mar"&gt;six bulletins&lt;/a&gt;, including one that addresses a critical vulnerability in all versions of Windows from Windows XP service pack 3 to Windows 7 service pack 1 and Windows Server 2008 R2. The rating means that the hole enables attackers to infect a system via the internet and inject malicious code. Other bulletins will address a privilege elevation flaw which affects the same span of Windows versions.&lt;/p&gt;</description></item><item><title>Microsoft's Patch Tuesday fixes critical vulnerabilities</title><link>https://omid.dev/2012/02/15/microsofts-patch-tuesday-fixes-critical-vulnerabilities/</link><pubDate>Wed, 15 Feb 2012 17:17:00 +0000</pubDate><guid>https://omid.dev/2012/02/15/microsofts-patch-tuesday-fixes-critical-vulnerabilities/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="http://lh5.ggpht.com/-tyZvt7vnyI4/TzvhhYJAlYI/AAAAAAAAEx4/1eEQDD7t5nY/s1600-h/Microsoft%25255B5%25255D.jpg" alt="Microsoft" /&gt;
&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The H-Online:&lt;/strong&gt; As expected, Microsoft has &lt;a href="http://blogs.technet.com/b/msrc/archive/2012/02/14/msrc-looks-back-at-ten-years-and-the-february-2012-bulletins.aspx"&gt;released&lt;/a&gt; nine bulletins to close a total of 21 holes in its products. Four of the bulletins close critical vulnerabilities in Windows, Internet Explorer, .NET and Silverlight, including an issue in the Windows kernel-mode drivers that became publicly known in December of last year.&lt;/p&gt;
&lt;p&gt;The company advises those responsible for prioritizing update deployment to focus on the critical patches for Internet Explorer and the C Runtime Library in Windows, as these could be exploited by an attacker to remotely execute arbitrary code on a victim&amp;rsquo;s system. For an attack to be successful, a user must first visit a malicious web page or open a specially crafted file. The other critical bulletins fix issues in .NET and Silverlight, as well as the Windows kernel. Microsoft notes that it has yet to see any active attacks exploiting these issues in the wild.&lt;/p&gt;</description></item><item><title>Patch Tuesday – Minor movements…</title><link>https://omid.dev/2010/05/11/patch-tuesday-minor-movements/</link><pubDate>Tue, 11 May 2010 22:43:00 +0000</pubDate><guid>https://omid.dev/2010/05/11/patch-tuesday-minor-movements/</guid><description>&lt;p&gt;Hey Admins…. It’s that time again. The second Tuesday is upon us and May so far hasn’t been demanding as far as patching goes.&lt;/p&gt;
&lt;p&gt;So far …. this month Microsoft has only issued two security announcements. &lt;a href="http://www.sophos.com/support/knowledgebase/article/110936.html"&gt;MS10-030&lt;/a&gt; and &lt;a href="http://www.sophos.com/support/knowledgebase/article/110937.html"&gt;MS10-031&lt;/a&gt;. Microsoft has rated both as critical – and both could result in remote code being executed.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.sophos.com/support/knowledgebase/article/110936.html"&gt;MS10-030&lt;/a&gt; resolves an integer overflow in POP3 &amp;amp; IMAP mail responses to Outlook Express and Windows Mail…. &lt;a href="http://www.sophos.com/support/knowledgebase/article/110937.html"&gt;MS10-031&lt;/a&gt; addresses a stack memory corruption related to the way that “Visual Basic for Applications” searches for ActiveX components, when host applications provide specially crafted files to the Visual Basic runtime.&lt;/p&gt;</description></item><item><title>Plenty of Updates on Patch Tuesday</title><link>https://omid.dev/2010/04/12/plenty-of-updates-on-patch-tuesday/</link><pubDate>Mon, 12 Apr 2010 18:52:00 +0000</pubDate><guid>https://omid.dev/2010/04/12/plenty-of-updates-on-patch-tuesday/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="http://lh3.ggpht.com/_vaUVXcmC3OI/S8NknZEG-OI/AAAAAAAAB6M/pc-UstgOkAY/s1600-h/microsoft_logo%5B6%5D.jpg" alt="microsoft_logo" /&gt;
Many patches are &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms10-apr.mspx"&gt;announced&lt;/a&gt; for tomorrow: The Redmond company expects to release 11 security bulletins. Of those 5 are rated critical, 5 important and 1 moderate. The patches belonging to the bulletins will close 25 security vulnerabilities in Windows, Exchange and in Office.&lt;/p&gt;
&lt;p&gt;&lt;img loading="lazy" src="http://lh6.ggpht.com/_vaUVXcmC3OI/S8NkyzGfQOI/AAAAAAAAB6U/-d1kFCSr044/s1600-h/acrobat_logo%5B3%5D.png" alt="acrobat_logo" /&gt;
Adobe &lt;a href="http://www.adobe.com/support/security/bulletins/apsb10-09.html"&gt;plans&lt;/a&gt; to deliver security updates for critical vulnerabilities in Adobe Reader and Acrobat for all supported platforms tomorrow. Additionally, the automatic updater will be activated with the patches so in future updates get installed silent.&lt;/p&gt;</description></item><item><title>Adobe Patch Tuesday news: auto updater coming</title><link>https://omid.dev/2010/04/09/adobe-patch-tuesday-news-auto-updater-coming/</link><pubDate>Fri, 09 Apr 2010 21:44:00 +0000</pubDate><guid>https://omid.dev/2010/04/09/adobe-patch-tuesday-news-auto-updater-coming/</guid><description>&lt;p&gt;Adobe has announced that it will release an updater along with Adobe Reader and Acrobat versions 9.3.2 and 8.2.2 on patch Tuesday next week.&lt;/p&gt;
&lt;p&gt;On the Adobe blog, Steve Gottwals wrote: “…we have been testing a new updater technology with select beta customers since our October 13, 2009 quarterly update. The purpose of the new updater is to keep end-users up-to-date in a much more streamlined and automated way.&lt;/p&gt;
&lt;p&gt;“During our quarterly update on January 12, 2010, and then again for an out-of-cycle update on February 16, 2010, we exercised the new updater with our beta testers. This allowed us to test a variety of network configurations encountered on the Internet in order to ensure a robust update experience. That beta process has been a successful one, and we&amp;rsquo;ve incorporated several positive changes to the end-user experience and system operation. Now, we&amp;rsquo;re ready for the next phase of deployment.”&lt;/p&gt;</description></item><item><title>Patch Tuesday next week</title><link>https://omid.dev/2010/04/08/patch-tuesday-next-week/</link><pubDate>Thu, 08 Apr 2010 22:10:00 +0000</pubDate><guid>https://omid.dev/2010/04/08/patch-tuesday-next-week/</guid><description>&lt;p&gt;Microsoft has put the PC-using world on notice that next Tuesday there will be 11 bulletins released addressing 25 vulnerabilities in Windows, Exchange and Office.&lt;/p&gt;
&lt;p&gt;Jerry Bryant, Group Manager of Microsoft’s Response Communications, said:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;“I also want to point out to customers that we will be closing the following open Security Advisories with next week’s updates:&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;— Microsoft Security Advisory 981169 – Vulnerability in VBScript could allow remote code execution.&lt;/p&gt;</description></item><item><title>It's not dead yet: Microsoft's out-of-band IE6 fix impacts IE8</title><link>https://omid.dev/2010/03/30/its-not-dead-yet-microsofts-out-of-band-ie6-fix-impacts-ie8/</link><pubDate>Tue, 30 Mar 2010 14:27:00 +0000</pubDate><guid>https://omid.dev/2010/03/30/its-not-dead-yet-microsofts-out-of-band-ie6-fix-impacts-ie8/</guid><description>&lt;p&gt;Last month, Microsoft sent flowers to a mock funeral for Internet Explorer 6, in a show of support for the ideal that the old browser should be declared defunct worldwide. But for a few years yet, the company is still bound to support the product for those users (generally businesses) who refuse to upgrade it. That&amp;rsquo;s why new exploits that continue to target old browsers, such as IE6 and IE7, continue to get attention even a full year after the proper security fix — IE8 — has been deployed.&lt;/p&gt;</description></item><item><title>Internet Explorer 0-day targeted in spam runs</title><link>https://omid.dev/2010/03/12/internet-explorer-0-day-targeted-in-spam-runs/</link><pubDate>Fri, 12 Mar 2010 14:06:00 +0000</pubDate><guid>https://omid.dev/2010/03/12/internet-explorer-0-day-targeted-in-spam-runs/</guid><description>&lt;p&gt;Hot on the heels of the Patch Tuesday announcements yesterday, came the &lt;a href="http://www.microsoft.com/technet/security/advisory/981374.mspx"&gt;announcement&lt;/a&gt; of a new zero-day in Internet Explorer (&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0806"&gt;CVE-2010-0806&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;Whilst checking through some URLs supposedly serving up malicious code to exploit this vulnerability, I noticed a link to some spam runs from earlier in the week. On March 8th SophosLabs saw spam messages attempting to trick the recipient into visiting rogue web pages. Messages used at least two social engineering tricks to lure victims into clicking the malicious link.&lt;/p&gt;</description></item><item><title>Exploit Code for IE 0-day vulnerability</title><link>https://omid.dev/2010/03/12/exploit-code-for-ie-0-day-vulnerability/</link><pubDate>Fri, 12 Mar 2010 13:48:00 +0000</pubDate><guid>https://omid.dev/2010/03/12/exploit-code-for-ie-0-day-vulnerability/</guid><description>&lt;p&gt;&lt;a href="https://omid.dev/images/2010/03/microsoft_logo-164de44b.jpg"&gt;&lt;img loading="lazy" src="https://omid.dev/images/2010/03/microsoft_logo.jpg" alt="" /&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Exploit code for the the zero-day vulnerability in &lt;a href="http://www.microsoft.com/technet/security/advisory/981374.mspx"&gt;Internet Explorer&lt;/a&gt; has been added to the Metasploit framework. According to an email HD Moore wrote to ZDNet’s Ryan Naraine, the exploit works quite reliable – successful 50% of the times on Windows XP with SP2 and SP3 with IE7 and deactivated Data Execution Prevention (DEP).&lt;/p&gt;
&lt;p&gt;The security hole got reported yesterday on Microsoft’s March 2010 &lt;a href="http://boelectronic.blogspot.com/2010/03/microsoft-patch-tuesday-march-2010.html"&gt;Patch Tuesday&lt;/a&gt;. Drive-by-Download-Exploits are likely to appear now as the Metasploit framework is open source and the exploit can now be abused even by script kiddies. Time to change the default browser – Microsoft just released a new &lt;a href="http://boelectronic.blogspot.com/2010/03/browser-choice.html"&gt;browser choice&lt;/a&gt; screen which allows for exactly that!&lt;/p&gt;</description></item><item><title>Microsoft Patch Tuesday – March 2010</title><link>https://omid.dev/2010/03/10/microsoft-patch-tuesday-march-2010/</link><pubDate>Wed, 10 Mar 2010 10:19:00 +0000</pubDate><guid>https://omid.dev/2010/03/10/microsoft-patch-tuesday-march-2010/</guid><description>&lt;p&gt;Hello and welcome to this month’s blog on the Microsoft patch releases. This is a fairly quiet month—the vendor is releasing two bulletins covering a total of eight vulnerabilities.&lt;/p&gt;
&lt;p&gt;All of the issues are rated “Important” this month: seven affecting Office/Excel and one affecting Movie Maker and Producer. All of the issues are file-based remote code-execution vulnerabilities in the context of the currently logged-in user.&lt;/p&gt;
&lt;p&gt;Microsoft also released a security advisory (&lt;a href="http://www.microsoft.com/technet/security/advisory/981374.mspx"&gt;981374&lt;/a&gt;) today regarding a publicly disclosed vulnerability affecting Internet Explorer 6 and 7. Limited, targeted attacks exploiting this issue have been detected in the wild.&lt;/p&gt;</description></item><item><title>Patch Tuesday coming next week</title><link>https://omid.dev/2010/03/05/patch-tuesday-coming-next-week/</link><pubDate>Fri, 05 Mar 2010 19:37:00 +0000</pubDate><guid>https://omid.dev/2010/03/05/patch-tuesday-coming-next-week/</guid><description>&lt;p&gt;Microsoft has issued an advance notification for Patch Tuesday next week. The company said it expects to issue two patches, one for Windows and one for Office. Both are intended to patch vulnerabilities that could allow remote code execution and both are rated “important.”&lt;/p&gt;
&lt;p&gt;Microsoft Security Bulletin Advance Notification for March 2010 &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms10-mar.mspx"&gt;here&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>WinXP users: hold off on installing MS010–15 [BSOD]</title><link>https://omid.dev/2010/02/12/winxp-users-hold-off-on-installing-ms010-15-bsod/</link><pubDate>Fri, 12 Feb 2010 22:19:00 +0000</pubDate><guid>https://omid.dev/2010/02/12/winxp-users-hold-off-on-installing-ms010-15-bsod/</guid><description>&lt;p&gt;&lt;a href="https://omid.dev/images/2010/02/bsod-94b2cc3c.png"&gt;&lt;img loading="lazy" src="https://omid.dev/images/2010/02/bsod.png" alt="" /&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Security blogger Brian Krebs is reporting that some Windows XP users are reporting blue screen of death on reboot after installing Microsoft’s Tuesday patch KB977165 (MS010–15: “Vulnerabilities in Windows kernel could allow elevation of privilege.”)&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;“Turns out, a non-trivial number of XP users are reporting that their systems suffer from the dreaded Blue Screen of Death (BSoD) and fall into an interminable reboot loop after installing the latest batch of patches from Redmond,”&lt;/p&gt;</description></item><item><title>Microsoft will patch Internet Explorer today</title><link>https://omid.dev/2010/01/21/microsoft-will-patch-internet-explorer-today/</link><pubDate>Thu, 21 Jan 2010 19:31:00 +0000</pubDate><guid>https://omid.dev/2010/01/21/microsoft-will-patch-internet-explorer-today/</guid><description>&lt;p&gt;Microsoft has said it will issue an out-of-band patch today for critical vulnerabilities in Internet Explorer that allow remote execution of code. The company said yesterday it would not wait until the February “Patch Tuesday” to fix the vulnerabilities.&lt;/p&gt;
&lt;p&gt;The much discussed “Aurora” vulnerabilities in IE have been held at least partially responsible for cyber attacks on Google and more then two dozen other major companies. The attacks on Google were aimed at Gmail accounts of dissidents and Google’s source code. The attacks on the other companies were aimed at stealing intellectual property.&lt;/p&gt;</description></item><item><title>Plenty of Updates on Patch Tuesday</title><link>https://omid.dev/2010/01/13/plenty-of-updates-on-patch-tuesday-2/</link><pubDate>Wed, 13 Jan 2010 12:11:00 +0000</pubDate><guid>https://omid.dev/2010/01/13/plenty-of-updates-on-patch-tuesday-2/</guid><description>&lt;p&gt;This Black Tuesday was different as anticipated – Microsoft releases only one security bulletin, but other companies “jumped in” and deliver updates now as well.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://omid.dev/images/2010/01/microsoft_logo-fb949cef.jpg"&gt;&lt;img loading="lazy" src="https://omid.dev/images/2010/01/microsoft_logo.jpg" alt="" /&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;For the windows operating systems, only &lt;a href="http://www.microsoft.com/technet/security/Bulletin/MS10-jan.mspx"&gt;one Security Bulletin&lt;/a&gt; was released. &lt;a href="http://www.microsoft.com/technet/security/Bulletin/MS10-001.mspx"&gt;MS10-001&lt;/a&gt; deals with a vulnerability in the decompression routines of the Embeded OpenType Font Engine. This means that especially in Windows 2000, programs like Internet Explorer, Word or PowerPoint for example which render EOT fonts can put the system at risk when viewing manipulated contents. In newer operating systems the flawed code is used differently so that Microsoft assumes that it isn’t exploitable there.&lt;/p&gt;</description></item><item><title>Adobe Reader, Acrobat, Flash Player updater coming</title><link>https://omid.dev/2010/01/06/adobe-reader-acrobat-flash-player-updater-coming/</link><pubDate>Wed, 06 Jan 2010 14:58:00 +0000</pubDate><guid>https://omid.dev/2010/01/06/adobe-reader-acrobat-flash-player-updater-coming/</guid><description>&lt;p&gt;There has been extensive news coverage this week of Adobe’s plans for ramped-up security in its popular Reader, Acrobat and Flash Player applications, especially the Reader and Acrobat updates promised next week.&lt;/p&gt;
&lt;p&gt;A vulnerability that was publicized in December in Reader and Acrobat allows an attacker to execute arbitrary code with a specially crafted PDF file using ZLib compressed streams. In a short time, proof-of-concept code was made public. In the past week, anti-virus companies began intercepting malicious .pdf files that exploit the vulnerability to install a back door on victims’ machines.&lt;/p&gt;</description></item><item><title>Critical Adobe Flash Update</title><link>https://omid.dev/2009/12/09/critical-adobe-flash-update/</link><pubDate>Wed, 09 Dec 2009 00:42:00 +0000</pubDate><guid>https://omid.dev/2009/12/09/critical-adobe-flash-update/</guid><description>&lt;p&gt;It&amp;rsquo;s the second Tuesday of the month and there are important updates being released.&lt;/p&gt;
&lt;p&gt;From Microsoft, of course, but also from Adobe.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://omid.dev/images/2009/12/Adobe-Security-bulletin-APSB09-19-174fba5e.png"&gt;&lt;img loading="lazy" src="https://omid.dev/images/2009/12/Adobe-Security-bulletin-APSB09-19.png" alt="" /&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;There&amp;rsquo;s a &lt;a href="http://www.itpro.co.uk/618487/adobe-software-hit-again-by-hackers"&gt;critical security issue in Adobe Flash Player&lt;/a&gt; 10.0.32.18 and earlier.&lt;/p&gt;
&lt;p&gt;It&amp;rsquo;s important that organizations deploy these updates before the Christmas holiday reduces IT staffing. Fortunately, this patch cycle is as early as can be landing on the 8th so there&amp;rsquo;s still time to test and deploy.&lt;/p&gt;</description></item></channel></rss>