Microsoft still using undercover patches

Status
Not open for further replies.

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
Microsoft updates regularly contain fixes for security vulnerabilities which are not listed in its security bulletins. Microsoft defends these 'silent updates', as they are known within the security community, in a blog posting by its Security Research & Defense team.

When a security bug is fixed, the security team not only checks adjacent code for further vulnerabilities, it also looks for similar bugs elsewhere. It also occasionally lets fuzzers loose on the program in question. Microsoft designates such finds as 'variants', and they are defused with a minimum of fuss. They do, however, affect the classification given in bulletins. It can easily be the case that Microsoft increases the exploitability index of a bulletin due to a non-publicly disclosed variant.

Such security vulnerabilities also go unrecorded in the Common Vulnerabilities and Exposures (CVE) database, which is frequently used for comparative studies. Microsoft justifies not applying for CVE numbers for these 'variants' by pointing out that the CVE project purports to be a list of "publicly known" security vulnerabilities. The company points out that this would not apply to security issues discovered internally.

More details - link
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top