Version: 2008
  • On GameSpot: So-called 'Halo killer' gets 23 to life

October 20, 2005 4:29 PM PDT

More trouble with Microsoft patches

  • 8 comments
Microsoft's latest batch of security fixes keeps causing trouble for some users.

A "critical" patch for a problem in a Windows component for streaming media, called DirectShow, apparently isn't as straightforward as Microsoft thought. Some Windows 2000 users have applied the incorrect patch, leaving their computers vulnerable even though they think they've patched up, Microsoft said Thursday.

"A limited amount of customers, who may have obtained the wrong security update for their version of DirectX, may think they are protected when, in fact, they are not," a Microsoft representative said in an e-mailed statement. "This only affects users who have selected the wrong package manually." DirectX contains DirectShow.

Microsoft on Wednesday published its second advisory in as many weeks for users to deal with trouble arising from this month's patch release. Last week the software maker said another critical patch could cause problems for users who changed specific Windows security settings.

The latest patching issue deals with the fixes in security bulletin MS05-050. The problem occurs when Windows 2000 users who have DirectX 8.0 or 9.0 mistakenly apply the patch for DirectX 7.0. The computer will still be vulnerable to the flaw, while the user won't be notified that the system is not updated, Microsoft said.

Windows 2000 users who obtain security patches automatically through Microsoft's patching tools or who accurately followed the steps in the security bulletin are protected, the Microsoft representative said.

Users probably applied the wrong patch because Microsoft's security bulletin was unclear, said Brian Grayek, chief technology officer at Preventsys, a vulnerability management company in Carlsbad, Calif. "The vendor, no matter who, has to be responsible for being crystal clear on remediation," he said.

While Microsoft could have perhaps published a clearer bulletin, administrators are ultimately responsible for their systems, said Susan Bradley, an independent security consultant and Microsoft Most Valuable Professional.

"At the end of the day Microsoft is not responsible for my network, I am," Bradley said in an e-mail interview. "If I don't have a clear understanding of what I have installed, whose fault is that?"

Microsoft offers guidance for Windows 2000 users who think they may have applied the wrong update in an article on its Web site.

See more CNET content tagged:
DirectX, Microsoft Windows 2000, patch, Microsoft Corp., security

Add a Comment (Log in or register) (8 Comments)
  • prev
  • 1
  • next
Classic
by mcadoar October 20, 2005 5:50 PM PDT
It's funny to me how microsoft never releases a patch to fix a bad patch. If they mess up a patch, they always put a footnote about it on their site and expect end users to fix what they patched wrong.

Why not just release a patch over windows update to fix the problem with this patch?
Reply to this comment
Not MS' fault
by DrakeLoneStar October 20, 2005 6:47 PM PDT
The patch works correctly.

The users applied the patch over a version of DX that the patch does not address.

The system is not messed up, it just isn't patched (because the user isn't running the version of DX that needs the patch.)

Stop blaming other people for your own problems.
View all 2 replies
Microsoft
by Roman12 October 20, 2005 7:31 PM PDT
Thats how it works, they relase a patches, and then they release some other patches that the first ones did not cover, and then they must make more patches to cover up problems the first patches created. And so on. It's an endless loop.
__________________________________
R.K.
http://www.Remove-All-Spyware.com/
Blaming the users!
by technewsjunkie October 20, 2005 6:53 PM PDT
I love how a LOT of Techies like to blame users for "not
knowing" what they are somehow supposed to know! Unlike
these techies, MOST people use computers as tools for word
processing, etc and don't tinker or explore them. This is the vast
majority of users.

I have been horrified at Microsoft's update site over the years.
There are lists and lists of "appropriate" software, with
convoluted descriptions and "install order" (must install this
before that - or your screwed). Sheesh. They really don't get it.
Reply to this comment
Has anybody heard of TESTING.
by The Vanish October 21, 2005 2:52 PM PDT
Has anybody heard of TESTING. DUH!!! before you send a patch out make sure the patch is tested first. And I am talking to the people at Microsoft.
Reply to this comment
Testing?
by October 24, 2005 3:59 PM PDT
Testing!? What's that? Ha. Microsoft don't need to test. They think they are the best coders since they cover 90% of the market.
(8 Comments)
  • prev
  • 1
  • next
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Microsoft (0.00%) 0.00 28.52
Dow Jones Industrials (0.00%) 0.00 10,023.42
S&P 500 (0.00%) 0.00 1,069.30
NASDAQ (0.00%) 0.00 2,112.44
CNET TECH (0.00%) 0.00 1,538.38
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right