Waaaay back in July I had a “runin” of sorts with the auditor over a CERT advisory.

Well, CERT has issued a new advisory. Upgrade to SP2 as soon as possible. Do not wait 30 days. Do not wait for the CD to be delivered. Upgrade now.

Fun. I’ve been saying the same thing in hundreds of debates for weeks now. The time where you can simply sit back and wait to see if critical patches are going to be reneg’d on is past. Test everything first. But when you are done with your testing, install. Fast. Because the mean time to a virus being deployed after an exploit is found is down to less than a week.

That scares me.

Sadly, this advisory will not get nearly the publicity that the anti-IE advisory got. Which is, I guess, typical. However thankfully I’ll have this advisory archived here at Ensight so I can pull it up should the auditor come’a runnin’ again.