Microsoft set to deliver two emergency updates Tuesday

In an unusual move, Microsoft late Friday announced that it plans to release two out-of-band security patches next week.

The software giant, in an advisory, said it expects to release two patches on Tuesday: one aimed at development tools suite Visual Studio, the other for Internet Explorer.

Mike Reavey, group manager of the Microsoft Security Response Center, said in a blog post Friday that the update is meant to address a "single, overall issue" in all versions of Windows, but did not provide further details. Customers who currently are fully patched are protected against "known attacks" related to the issue, he said.

"While we can't go into specifics about the issue prior to the release, we can say that the Visual Studio bulletin will address an issue that can affect certain types of applications," Reavey wrote. "The Internet Explorer bulletin will provide defense-in-depth changes to Internet Explorer to help provide additional protections for the issues addressed by the Visual Studio bulletin."

In addition, the IE update will resolve a number of "critical" vulnerabilities, unrelated to Visual Studio, that previously had been privately disclosed.

Microsoft typically releases its security updates on the second Tuesday of the month. This marks the first time that the company has gone off cycle since December, when it pushed out an emergency fix for Internet Explorer.


More in News

Privacy-bolstering "Apps Act" introduced in House

The bill would provide consumers nationwide with similar protections already enforced by a California law.

Microsoft readies permanent fix for Internet Explorer bug used in energy attacks

Microsoft is prepping a whopper of a security update that will close 33 vulnerabilities, likely including an Internet Explorer (IE) flaw that has been used in targeted website attacks against the U.S. government.

Weakness in Adobe ColdFusion allowed court hackers access to 160K SSNs

Up to 160,000 Social Security numbers and one million driver's license numbers may have been accessed by intruders.