For the month of December we are looking out for at least seven patches for the month. When I say at least, it's possible that we are going to see some additional updates as part of Microsoft's Out of Band patch release process.
These non-Patch Tuesday updates are called out-of-band (OOB) patches and may be released anytime through the month. There are quite a few requirements before Microsoft will release an OOB update, some of which include;
- Is this particular vulnerability serious enough to require the release of a patch out of the normal Patch Tuesday cycle?
- How widespread and immediate is the attack?
- Is the next patch release cycle near enough to warrant waiting a few days or a week?
- Will the rushed development and release of a quick patch likely disturb program functionality, perhaps producing more trouble than it resolves?
- Is the threat stable, or is it evolving (or likely to evolve) day by day?