Tue, 17/02/09 – 18:00 | No Comment

US-CERT is aware of a public report indicating active exploitation of a previously patched vulnerability in Microsoft Internet Explorer 7. This vulnerability was addressed in Microsoft Security Advisory MS09-002. …

Read the full story »
Articles

Patch management and related articles.

Bulletins

Microsoft’s monthly security bulletins.

Downloads

Security-related downloads from Microsoft download center.

Exploits

Various exploits seen in the wild.

KB Articles

Microsoft knowledge base articles.


Home » Articles, Microsoft

Treat these like Service Packs

Posted on Monday, 16 February 2009No Comment

I posted this to someone today and thought I’d blog this here as well: Regarding the patches that came out last week, consider two of them to be Service Packs and plan accordingly:  There are two BIG hunking patches in this go round that one really needs to treat like service packs. 1.  Exchange.  This is a denial of service and there’s no mitigation.  Big whoop they will target Vlad first and his big Exchange servers first, I can make a backup and install carefully.  You are replacing store.exe so it’s like it’s a sp1 or sp2.  Treat accordingly.  2007 does not need a reboot but I have seen these Update rollups sometimes need to be reinstalled as the initial install may mess up.  2k3 does need a reboot and a mere stopping of services and restarting on a SBS 2k3 box isn’t enough. 2.  SQL and on a SBS box we have ‘em coming out of our ears.  It’s replacing SQL engine as well.  Also treat like a service pack.  Only nails you if you have an external web site exposed and they can get in through cross site scripting, so I don’t see that we should be patching quickly on this one, we have time.  Treat also like a service pack as if the permissions in that database are horked you are calling a PSS SQL expert as there’s no easy blog answer as someone has to dig out the log file and read it

View original post here: 
Treat these like Service Packs


Tags: , , , , , , , ,

Related posts

Leave a comment!

Add your comment below, or trackback from your own site. You can also subscribe to these comments via RSS.

Be nice. Keep it clean. Stay on topic. No spam.

You can use these tags:
<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

This is a Gravatar-enabled weblog. To get your own globally-recognized-avatar, please register at Gravatar.

Comment spam protected by SpamBam
(1157 spam filtered)