Microsoft March Patch Pre-Announcement
Microsoft released its pre-announcement for the upcoming patch Tuesday. The summary indicates a total of 5 bulletins, 2 are critical with remote code execution and 3 Important with a mix of security feature bypass and elevation of privileges. The announcement is available here.
Reminder
Last patch Tuesday for both Windows XP(SP3) and Office 2003 is next month April 8, 2014. This means that any new vulnerabilities discovered in Windows XP or Office 2003 after its “end of life” will no longer be addressed by new security updates from Microsoft. It is now time to upgrade on the Windows 7 or 8. ISC has pool going title "The end of XP is looming where are you at?"
[1] http://technet.microsoft.com/en-us/security/bulletin/ms14-mar
[2] http://blogs.technet.com/b/kdean/archive/2014/01/12/windows-xp-end-of-life-amp-support-options.aspx
[3] http://blogs.technet.com/b/security/archive/2013/04/09/the-countdown-begins-support-for-windows-xp-ends-on-april-8-2014.aspx
[4] http://blogs.technet.com/b/security/archive/2013/08/15/the-risk-of-running-windows-xp-after-support-ends.aspx
[5] https://isc.sans.edu/poll.html
-----------
Guy Bruneau IPSS Inc. gbruneau at isc dot sans dot edu
Comments