Microsoft's 3-day patching directive comes with added operational risk

speckx1 pts0 comments

Microsoft’s 3-day patching directive comes with added operational risk | CSO Online

Editions

Search

Menu

Topics

Close

Analytics<br>Application Security<br>Artificial Intelligence<br>Business Continuity<br>Business Operations<br>Careers<br>Cloud Security<br>Compliance<br>Critical Infrastructure<br>Cybercrime<br>Enterprise Buyer’s Guides<br>Generative AI<br>Identity and Access Management<br>Industry<br>IT Leadership<br>IT Management<br>Network Security<br>Physical Security<br>Privacy<br>Risk Management<br>Security<br>Security Infrastructure<br>Software Development<br>Vulnerabilities

AmericasUnited States

AsiaASEAN<br>India

EuropeUnited Kingdom

OceaniaAustralia

by John Leyden

Senior Writer

Microsoft’s 3-day patching directive comes with added operational risk

Feature

Jul 23, 20267 mins

Microsoft 365 Director Jeremy Chapman this month took to video to tell Windows admins that the days of delaying security patches are over.

Complex enterprise systems and historic incidents involving patch problems have caused many admins to hold fire on immediately applying security patches, in many cases deferring patch rollouts for two to four weeks or more to ensure stability. Microsoft argues that this cautious approach, though understandable, is no longer viable because AI is accelerating the discovery and exploitation of software vulnerabilities.

As a result, Microsoft has advised admins to act on patches within three days.

Independent experts agree with Microsoft&rsquo;s diagnosis of the problems posed by AI-powered vulnerability discovery, but many say Microsoft&rsquo;s three-day remediation window is unrealistic for large enterprises with heavy testing, change-control, and compatibility constraints.

Instead of taking a blanket approach, enterprises need to focus more on quickly resolving those vulnerabilities that are under active exploitation and relevant to their environments, according to critics of Microsoft&rsquo;s revised approach.

Tighter patching deadlines

Microsoft&rsquo;s revised vulnerability remediation advice comes in the wake of its work with Anthropic&rsquo;s Project Glasswing and findings from Microsoft&rsquo;s own MDASH multi-model agentic scanning harness. Tighter patching deadlines are configurable via Windows Autopatch and Microsoft Intune or update tooling options such as Microsoft Configuration Manager and Windows Server Update Services.

As IT environments become increasingly more complex, inadvertent issues can occur with what appears to be a simple patch.

Unique or complex deployments may not be compatible with a patch, resulting in potential data corruption, system shutdown, or the dreaded &ldquo;Blue Screen of Death.&rdquo; Multiple vendors in the operating system and the enterprise software and security market have released patches that have broken products and caused outages, so the issue goes well beyond Windows shops.

Increasing both the volume and the speed of patching is unsustainable for most security teams because organizations are already struggling with successful remediation as it is.

&ldquo;Many organizations have patch windows, review cycles, and test environments to identify these issues prior to patching production environments,&rdquo; says Scott Caveza, senior research manager at exposure management and vulnerability assessment firm Tenable. &ldquo;Organizations lacking the resources for extended validation risk deploying faulty patches that cause downtime or force last-minute configuration changes.&rdquo;

Caveza adds: &ldquo;The mitigation steps will vary for each organization, but blindly relying on auto-updates without contextual validation is not a defensible security posture.&rdquo;

CISA&rsquo;s Known Exploited Vulnerabilities list and other industry data suggest that only a small fraction of disclosed vulnerabilities are confirmed as exploited in the wild.

&ldquo;[Enterprises should focus on] identifying vulnerabilities with credible and functional PoCs, verified exploitation, or sustained attention from ransomware groups, threat actors, and botnets,&rdquo; says Caitlin Condon, vice president of security research at VulnCheck. &ldquo;Timely exploit intelligence helps organizations identify the bugs that require immediate attention, while allowing lower-risk issues to proceed through appropriate testing and change control.&rdquo;

Other independent experts are more sympathetic to Microsoft&rsquo;s argument that AI has made vulnerability discovery and exploit development faster than ever and, as a result, the risks of delaying patches are far greater.

&ldquo;Organizations sometimes delay patches to protect the uptime of critical systems, and many updates still require a restart,&rdquo; says Danny Jenkins, CEO and co-founder at endpoint protection technology vendor ThreatLocker. &ldquo;Some teams also stay one update cycle behind because they are concerned that a new patch could introduce bugs or break an overlooked dependency. Unfortunately, delaying patches to preserve uptime is becoming much harder to...

microsoft security patches rsquo ldquo patching

Related Articles