Most Popular Stories
- 3 ways for CIOs to become business leaders
- Chrome 17's new features enhance speed, security
- FBI insists cloud providers meet strict security requirements
- Spotlight: Intel launches 520 Series solid-state drive
- Bug in Trendnet webcams exposes them to public viewing
- Multiple monitors makes some multitasking faster, easier
Events
- COMPTEL PLUS Spring 2012
April 15-18 — San Francisco, CA - Customer Engagement Technology World
March 28-29, 2012 — San Francisco - The AIIM Conference 2012
March 20-22, 2012 — San Francisco, CA - The AIIM Conference 2012
March 20-22, 2012 — San Francisco, CA
Sponsored Links
Free Newsletter
HOT TOPICS >> The tech world's top flops and fiascos of 2011 | Top 8 features in Windows 8 | Paul's Q&As
INDUSTRY >> Healthcare IT | Government IT | Financial Services IT | Biotech IT | Compliance IT
Free Newsletter
Latest News
Popular Topics
Whitepapers
- Whitepaper: Integrated Analytics and WCM Can Improve Performance & ROI
- Enterprise Digital Assistant Leverage in the Emerging Mobile Enterprise
- Enterprise Portals: Harnessing Portal Power
- Security Intelligence: Enabling Security Monitoring for Landscapes
- The Shortcut Guide to Secure, Managed File Transfer
- End-of-life solution management for mobile devices reduces MNCs' security, compliance and sustainability risks
Microsoft patches XML flaw, still no Visual Studio fix
Another month, another Patch Tuesday. This month's iteration will find Microsoft patching the zero-day flaw in XML Core Services, in addition to other flaws in Windows XP and Internet Explorer, some of which have been deemed "critical". The company has not yet announced a fix for another zero-day flaw, in Visual Studio 2005, which was identified last month.
I think it's worth questioning if this whole "Patch Tuesday" thing is really a good idea. While it makes life easier for IT folks (who would otherwise have to identify and install patches on a patch-by-patch basis) it also makes life easier for hackers, who probably know that they have a set window of opportunity for exploiting vulnerabilities until they are patched. As in the case of Visual Studio, Microsoft sometimes even extends the deadline for hacker submissions, so to speak. Is it really wise for the company to address security concerns on a monthly schedule when exploits are being released every day? Let me know what you think in the comments section.
For more on November's Patch Tuesday:
- see this ZDnet article
Related Stories
- Patch Tuesday: Two's company
- Microsoft Patch Tuesday fixes clippy flaw
- Firefox 2/IE 7 animated cursor exploit on the way
- New Microsoft Word zero-day attack on the loose
- Microsoft addresses many bugs in this month's Patch Tuesday
- Microsoft plans small Patch Tuesday for January
- April Patch Tuesday cometh
- IE URL bug could lead to hijacking
- Patch Tuesday fixes Word, Outlook, IE
- Patch Tuesday brings critical IE, Windows fixes
Home
| Subscribe | Advertise | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2011 FierceMarkets. All rights reserved. |
![]() |




