One Fix Expected for Patch Tuesday
Microsoft's first security update rollout of 2009 may be a quiet one, according to an advance notification released Thursday. January's Patch Tuesday will consist of just one "critical" patch.
The light release follows a December patch cycle that covered the most vulnerabilities in the history of Patch Tuesday, as well as included an out-of-cycle patch for Internet Explorer. This latest bulletin addresses remote code execution and will cover Windows 2000, Windows XP and Windows Server 2003. Its severity has been deemed merely "moderate" for Vista and Windows Server 2008.
With a few known flaws left to be fixed from the end of 2008 -- one in WordPad Text Converter and another in the SQL Server database software, for instance -- there is a bit of speculation over which Windows component the upcoming patch will fix. Andrew Storms, director of security operations for independent security vendor nCircle, thinks Microsoft will fix a "known" Windows flaw rather than a zero-day bug.