Three guys got together over pints in February 2009 and talked about how one of the issues facing Technical Professionals today is keeping their systems patched and up to date. This issue was brought up to them at a User Group meeting they were attending (Ottawa Windows Server User Group) where we were participating in an “Ask the Microsoft Guy” panel discussion.
Over pints at D’Arcy McGee’s, Pierre Roman, Bruce Cowper and I decided we would try to help solve the issue of information overload regarding patching and put together a timely podcast to go live each “Patch Tuesday”.
- Use plain English terms and every day language that any Technical professional can understand – minimize “corporate speak”.
- Breakdown each Security Bulletin with summary information first followed by more details as to the impact an IT Pro would face.
- Outline mitigation factors in case patches couldn’t be tested or applied in a timely fashion
- Keep it top 20 minutes OR LESS. This one is critical – Keep It Simple, repeatable and get out of the IT Pros way to get on with their day.
- Have fun!
Have a listen directly from the embedded Silverlight player OR subscribe to the specific feed and download it to your iTunes / Zune software.
As always - if you have suggestions on making it better - please pass on your comments. Mail me directly – firstname.lastname@example.org
Subscribe to the podcast: (so you don't miss an episode)
Disclaimer: This podcast was produced with the best information available to us at the time of recording. Your primary source for all things Security Bulletin related should always be the Microsoft Security Response Center blog.
Bulletins discussed for November 10th, 2009:
- MS09-063 - Critical Vulnerability in Web Services on Devices API Could Allow Remote Code Execution (973565)
- MS09-064 - Critical Vulnerability in License Logging Server Could Allow Remote Code Execution (974783)
- MS09-065 - Critical Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (969947)
- MS09-066 - Important Vulnerability in Active Directory Could Allow Denial of Service (973309)
- MS09-067 - Important Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (972652)
- MS09-068 - Important Vulnerability in Microsoft Office Word Could Allow Remote Code Execution (976307)
- MS09-045 - Critical Vulnerability in JScript Scripting Engine Could Allow Remote Code Execution (971961)
- MS09-051 - Critical Vulnerabilities in Windows Media Runtime Could Allow Remote Code Execution (975682)
Podcast Participants: Pierre Roman, Bruce Cowper and myself.
Additional Technical Show Notes:
- Recorded at the local Starbucks across the street from the Ottawa offices of Microsoft Canada.
- Beverage of choice for this edition: Vanilla Latté and Chai Latté
- Get Security Essentials from www.microsoft.com/securityessentials
- Microsoft Security Intelligence Report (SIR) can be found here.