fbpx
patches and updates

Patch Tuesday and Updates

Patch Tuesday, also known as Update Tuesday refers to the established policy set by Microsoft and several other large software providers to push quality and security updates and fixes to their applications and programs. Since 2003 Microsoft have been releasing important updates on the second Tuesday of every month in order to address issues. Very important critical updates are released as soon as possible for obvious reasons.

Unfortunately what often follows a “patch Tuesday” is “exploit Wednesday”. When Microsoft release patches for security issues it often serves to highlight those vulnerabilities which can then be abused by attackers before people update their systems. This is why it is paramount to install critical security updates as soon as you can. Feature updates are less important and can in fact bring their own problems as new exploits and security holes are discovered.

Updates are Important

CrowdSrike updates

Microsoft have always recommended installing updates as soon as you can and are often waging a battle against the user to get them to set aside time for it to happen. In most cases people only turn on their computers when they need them, which means updating often gets in the way of actually using your computer. Many a working day has been extended annoyingly because of a Windows update starting just as you yourself want to finish.

The old adage, “if it ain’t broke, don’t fix it” still applies but it runs counter to the update strategy, many vendors, including Microsoft themselves, have broken many features as they release “updates”, such as losing microphone or camera functionality, or you find your printer no longer works. Microsoft generally release hotfixes when they can but there is no guarantee that full functionality will remain post-update.

Overall, the risks of exploit outweigh the risk of a bad update, so you must continue to update – Clive has a lot to say about patches and updates over on Smart Thinking Solutions. All problems will likely be resolved eventually in future updates.

Ben Parker – byline and other articles

Further Reading

This article was published before the CrowdStrike Global IT Outage

The Wednesday Bit on Monday – CrowdStrike Global IT Outage
The Cyber Security Fallout of CrowdStrike Global IT Outage