Microsoft security update cripples IE
Last week's MS07-069 update crashes IE6, IE7 on Windows XP, Vista for some — Microsoft Corp. confirmed today that it is investigating reports that a security update for Internet Explorer issued last week has crippled some users' ability to get on the Web.
Context & Ripple Effects
This is the third time in two years an Internet Explorer patch has backfired. A December 2005 update jammed up IE outright, and an August 2006 patch left patched machines open to attack — so MS07-069 crashing IE6 and IE7 lands on a documented pattern of quality-control failures in Microsoft's monthly security cycle.
The stakes are higher now than in 2005 because the failure spans both Windows XP and the year-old Vista, meaning the same broken update hits Microsoft's legacy install base and the platform it is trying to migrate everyone onto. With Microsoft confirming only that it is investigating, the company has no fix in hand as of December 17.
First-order effects
- Users on Windows XP and Vista who installed MS07-069 lose reliable web access through both IE6 and IE7, with no workaround confirmed by Microsoft yet.
- Microsoft's support channels absorb an investigation load spanning two OS versions and two browser versions while the bulletin itself remains officially recommended.
Second-order effects
- Enterprise IT administrators, already wary after the 2005 and 2006 incidents, gain fresh evidence for delaying or testing patches before deployment — slowing the very security updates MS07-069 was meant to deliver.
- Every crash report forces Microsoft to weigh pulling or reissuing the bulletin against leaving known-vulnerable machines unpatched, a trade-off competitors' browsers do not have to make.
Third-order effects
- If patch-induced breakage keeps recurring, trust in automatic updates erodes structurally: users and administrators learn to defer fixes, widening the window that malware exploits — the opposite of what the patch program exists to do.
- A browser that ships broken by its own vendor's update undermines confidence in the bundled-browser model itself, handing ammunition to arguments for browser choice independent of the operating system.
The trend: Microsoft's Patch Tuesday machine is colliding with its own QA limits, as a security-update pipeline built for speed repeatedly breaks the browser it is supposed to protect.