Microsoft is changing the way they distribute security bulletins. In the past, they’ve blasted out fairly technical bulletins to all subscribers, including the home users and other non-administrator types who took my advice and signed up for the bulletin service. It’s a litte daunting when Mom gets a security bulletin for Exchange 2000!
To make it easier for everyone to find out what’s what, their new process is a bit different:
- The existing technical bulletins stay around, but they’re now targeted at administrators, not end users
- In the future, new bulletins for end-user issues (like patches for IE or Office) will be released. These will be less technical, with links to more info on the MS web site.
- The rating system for vulnerabilities has changed. Since someone else already has a monopoly on color codes, Microsoft’s using a scale ranging from “critical” to “low”.
