Updated: Security researchers highlight more errors in Microsoft's patch creation process and warn that the mistakes are proving costly for users.
It's being called the "story of a dumb patch." A private security research firm has published an advisory with details on a fundamental mistake made by Microsoft Corp. that caused a security patch to ship without an adequate fix for the flaw it was meant to address.
Cesar Cerrudo, founder and CEO of Argeniss Information Security, found that the inadequate fix was included in the MS05-018 bulletin that shipped on April 12, leading to a situation where a new patch had to be created to provide comprehensive protection.
|