Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Microsoft Re-Releases Windows Security Update Pulled After Complaints

Microsoft has fixed and reissued a patch released earlier this month that left some users with the infamous ‘Blue Screen of Death.’

The patch in question is MS 14-045, which was released earlier this month as part of the Patch Tuesday update. After customers reported problems, Microsoft advised users to uninstall the original patch, and pulled it from the Windows Update service.

Microsoft has fixed and reissued a patch released earlier this month that left some users with the infamous ‘Blue Screen of Death.’

The patch in question is MS 14-045, which was released earlier this month as part of the Patch Tuesday update. After customers reported problems, Microsoft advised users to uninstall the original patch, and pulled it from the Windows Update service.

“This month we had our first roll out with additional non-security updates,” blogged Tracey Pretorius, director of Microsoft Trustworthy Computing. “A small number of customers experienced problems with a few of the updates. As soon as we became aware of some problems, we began a review and then immediately pulled the problematic updates, making these unavailable to download. We then began working on a plan to rerelease the affected updates.”

The security bulletin was meant to address three vulnerabilities in Windows, the most severe of which could allow an attacker to escalate privileges. The attacker would need valid logon credentials and be able to log on locally to exploit the issues.

While customers do not need to uninstall the previous version of the update before installing the latest edition, Microsoft strongly recommends it. In addition to the blue screens, other customers reported receiving ‘File in Use’ error messages and other problems.

“We encourage customers to install the security update as soon as possible. Customers with automatic updates enabled do not need to take any action,” blogged Pretorius. “If you don’t have Windows Update enabled, we encourage you to do so now. If you’re not sure whether you’ve enabled Windows Update, you can check here. For organizations, your IT Group, the team or person administering the network, would be the best place to check.”

Advertisement. Scroll to continue reading.

According to a new report from IBM’s X-Force team, the first half of 2014 saw roughly 3,900 new security vulnerabilities affecting 926 unique vendors. If this trend continues through the end of the year, the total projected vulnerabilities would fall below 8,000 – the first time the total has been that low since 2011, IBM noted. As was the case last year, roughly a third (34 percent in 2014 and 32 percent in 2014) of the vulnerabilities came from the top 10 enterprise software companies.

“Although overall vulnerability numbers are down for the first half of 2014, the impact to the top 10 enterprise software vendors remains consistent,” according to the report. “It is uncertain at this point whether this trend will continue through the end of the year as attackers continue to seek higher impact/higher potential reward targets or whether we will see an increase in the second half of the year in the number of disclosed vulnerabilities against smaller vendors and components, such as CMS plug-ins.”

Written By

Marketing professional with a background in journalism and a focus on IT security.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Jonathan Trull has joined Oracle as Global Head of Cyber Defense.

Plaid has appointed Sean Cassidy as Chief Information Security Officer.

Ann Barron-DiCamillo has been named Executive Vice President and Global Chief Information Security Officer at U.S. Bank.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.