LevelBlue + SentinelOne Partner to Deliver AI-Powered Managed Security Operations and Incident Response. Learn More

Microsoft Advance Notification for January 2014

Microsoft is scheduled to release the next security update for consumers on January 14th with affected Windows platforms, Microsoft Office software, and Microsoft Dynamics AX. This is one of the lightest security releases seen in some time with only four bulletins each rated "Important". Last year was pretty rough for administrators since each Microsoft security update contained at least one "Critical" vulnerability. These required affected systems to be upgraded immediately. By comparison, next Tuesdays release should be easier to remediate compared to previous security updates.

This does not mean that administrators should take the January security lightly. There is one bulletin in Microsoft Server software and Office that gives an attacker remote code execution capabilities. Additionally, there are two bulletins discussing vulnerabilities that allow an attacker to escalate privileges. December's Microsoft Patch Tuesday blog post mentioned a Windows Kernel elevation of privilege vulnerability (CVE-2013-5065, aka Kernel NDProxy Vulnerability) that has remained unpatched since November. It is highly anticipated that the January release will provide a fix for this particular vulnerability. This would be one of the higher priority patches since exploits have been observed in the wild taking advantage of this vulnerability in conjunction with an Adobe Reader vulnerability.

For a complete run-down of the January Microsoft security bulletins, please come back on January 14th. We hope to see you back soon!

ABOUT LEVELBLUE

LevelBlue secures what's next with intelligence-led security delivering visibility and speed to stop threats faster. As the world’s largest and most analyst-recognized pure-play managed security services provider, our AI-powered managed services and cyber expertise across managed, advisory, and incident response services help clients operate with confidence. Learn more about us.

https://www.levelblue.com/resources/blogs/internal-blog/how-to-create-a-blog-post/

Latest Intelligence

Discover how our specialists can tailor a security program to fit the needs of
your organization.

Request a Demo