Microsoft Fixes Critical Flaws with Patch Tuesday Updates

09.05.2012
Microsoft released a total of for May's Patch Tuesday. Four are rated as Important, and the other three are Critical, but two in particular are getting the most attention: and .

MS12-034 fixes 10 separate vulnerabilities spanning a range of Microsoft products including Windows, Office, .NET Framework, and Silverlight. It's unusual for Microsoft to lump so many products together in a single security bulletin or patch.

Wolfgang Kandek, CTO of , provides some background to explain the unusual patch . MS12-034 is the result of an effort by Microsoft to seek out other products using the same . This patch knocks out all of the other instances, and addresses a variety of other security issues in the affected products at the same time.

Andrew Storms, director of security operations for , isn't impressed by the bundled patch. Storms says, "The core of this bug fix is related to the vulnerabilities --a problem Microsoft fixed last year--so this bulletin also replaces a half dozen previously released bulletins. This is going to give the patch management folks some serious heartburn."

Tyler Reguly, technical manager security research and development at nCircle agrees. "MS12-034 is sheer craziness--it's going to be the most interesting and most painful part of the day for most IT security teams. There are multiple Office and .NET patches due to the overlap of products in this bulletin.

Storms recommends IT admins not spend too much time scratching their heads analyzing or trying to understand MS12-034. "Just install the patch as soon as you can, and then move on."