Microsoft says it has been working on a critical vulnerability in database software for more than eight months. Austrian security researcher went public with details of the vulnerability on Dec. 9, apparently after tiring of Microsoft’s lack of communication. Microsoft has urged users to deny permissions to the procedure that can be used to trigger the bug. Microsoft’s next scheduled update is set for Jan. 13, 2009, nearly three weeks from today. Security expert says he’s betting that Microsoft will release a patch soon.”]