News

12 Microsoft Patches Coming Tuesday

The Microsoft Security Response Center plans to publish 12 security bulletins next Tuesday, according to Thursday's advance notification.

At least four updates will address critical issues, Microsoft said -- although Redmond was vague about just how many critical updates it plans to release. Microsoft lumped the bulletins into several groups: eight of which affect Windows, two of which affect Office, one of which affects both Windows *and* Office, and an assortment of others that affect Microsoft Data Access Components (MDAC), Microsoft's malware and antivirus technologies (Microsoft Antigen, Microsoft Windows Defender, and Microsoft Forefront), and Visual Studio, among others.

Of the five Windows bulletins, the advance notification says that, "The highest Maximum Severity rating for these is Critical." At least one Windows bulletin, one Office bulletin, along with the combined Windows-Office bulletin and the malware and antivirus bulletin, merit severity ratings of "Critical."

Thursday's advance notification isn't always the last word in Patch Tuesday deliverables, of course. Last month, for example, Microsoft yanked several promised Windows patches from its Patch Tuesday payload. Redmond typically pulls a patch if it discovers problems during testing, or if it identifies other issues.

The software giant didn't say whether next Tuesday's patch haul will include fixes for any of several Word zero-day exploits now in circulation; nor did Microsoft indicate if next week's Patch Tuesday payload will address an Excel zero-day attack that first came to light last week.

With two Office-related bulletins in the offing, as well as a combined Windows and Office bulletin coming too, it's possible Microsoft plans to patch these vulnerabilities.

Microsoft customers will also see an update of the Windows Malicious Software Removal Tool on Tuesday. In addition, Microsoft plans to distribute two non-security high-priority updates next week via Windows Update (WU) and Software Update Services (SUS); along with eight non-security high priority updates via Microsoft Update (MU) and Windows Server Update Services (WSUS).

About the Author

Stephen Swoyer is a Nashville, TN-based freelance journalist who writes about technology.

Featured

  • Closeup of the new Copilot keyboard key

    Microsoft Updates Copilot To Add Context-Sensitive Agents to Teams, SharePoint

    Microsoft has rolled out a new public preview for collaborative "always on" agents in Microsoft 365 Copilot, bringing enhanced, context-aware tools into Teams channels, meetings, SharePoint sites, Planner workstreams and Viva Engage communities.

  • Windows 365 Cloud Apps Now Available for Public Preview

    Microsoft announced this week that Windows 365 Cloud Apps are now available for public preview. This aims to allow IT administrators to stream individual Windows applications from the cloud, removing the need to assign Cloud PCs to every user.

  • Report: Security Initiatives Can't Keep Pace with Cloud, AI Boom

    The increasingly fast adoption of hybrid, multicloud, and AI systems is easily outgrowing existing security measures, according to a recent global survey by the Cloud Security Alliance (CSA) and exposure management firm Tenable.

  • World Map Image

    Microsoft Taps Nebius in $17B AI Infrastructure Deal To Alleviate Cloud Strain

    Microsoft has signed a five-year, $17.4 billion agreement with Amsterdam-based Nebius Group to expand its AI computing capabilities through third-party GPU infrastructure.