Windows 10: Fully patched Win10 machine still showing vulnerabilities in IE11 according to Windows...

Discus and support Fully patched Win10 machine still showing vulnerabilities in IE11 according to Windows... in Windows 10 Installation and Upgrade to solve the problem; I have a Windows 10 machine build 10.0.18363.1316. It is licensed for Windows Defender ATP which is saying it has several vulnerabilities for IE11 due... Discussion in 'Windows 10 Installation and Upgrade' started by JeremyHagan, Jan 14, 2021.

  1. Fully patched Win10 machine still showing vulnerabilities in IE11 according to Windows...


    I have a Windows 10 machine build 10.0.18363.1316. It is licensed for Windows Defender ATP which is saying it has several vulnerabilities for IE11 due to it being out of date EG: CVE-2020-0847. I have checked and it is true, the EXE for IE is ver 11.00.18362.1 Microsoft Defender Security reports 11.1198.18362.0. However I have the latest CU for Windows 10 installed KB4598229. How is this possible that it has not been updated? The CVE is from March last year.

    According to this article the way to tell the update version of IE11 in Windows 10 is via the registry. On the vulnerable machine this is listed as KB4586768, which isn't an update for Windows 10, but a cumulative update for IE11 from November last year, however even this can't be accurate because the sample CVE I listed above was supposed to be patch March 2020.


    None of this makes sense. Any ideas on why IE is not properly patched?

    :)
     
    JeremyHagan, Jan 14, 2021
    #1
  2. Yukikaze Win User

    WPA2 Vulnerability Found

    A small update with regards to the Microsoft fix. The fix itself is sufficient to solve the issue on Windows, even if your WiFi device has no driver update, with one caveat:

    Does this security update fully address these vulnerabilities on Microsoft Platforms, or do I need to perform any additional steps to be fully protected?
    The provided security updates address the reported vulnerabilities; however, when affected Windows based systems enter a connected standby mode in low power situations, the vulnerable functionality may be offloaded to installed Wi-Fi hardware. To fully address potential vulnerabilities, you are also encouraged to contact your Wi-Fi hardware vendor to obtain updated device drivers. For a listing of affected vendors with links to their documentation, review the ICASI Multi-Vendor Vulnerability Disclosure statement here: http://www.icasi.org/wi-fi-protected-access-wpa-vulnerabilities

    Source: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-13080
     
    Yukikaze, Jan 14, 2021
    #2
  3. Taffy087 Win User
    Yet another Adobe Flash security hole that needs patching. Win10

    According to this Qualys article, Adobe released

    APSB16-36
    yesterday "to fix one 0-day vulnerability in Flash. The vulnerability is currently being used in active attacks and therefore Adobe released this emergency fix. If left un-patched, attackers can remotely take
    complete control of the machine."

    When will Microsoft release its update for its embedded Flash in Win10 please?
     
    Taffy087, Jan 14, 2021
    #3
  4. keiser__ Win User

    Fully patched Win10 machine still showing vulnerabilities in IE11 according to Windows...

    Patching windows 10 vulnerabilities

    Hi,

    I'm new to windows and to the community so excuse me if I miss some community guidelines.

    I've installed windows 10 (build number 14390) a few days ago, and today out of paranoia run a vulnerability scan using retina community. The report came out very colorful (6 high risk vulnerabilies) . I have almost nothing installed apart from the following:

    • Visual Studio Code
    • Visual Studio Community edition
    • Cmder
    • MongoDb/Nodejs with some Npm modules
    • VLC
    I was confused by the fact that almost all the vulnerabilities were Microsoft Office or Microsoft VB6 related and I don't have any of that installed.

    Any idea where should I look for patches or how to proceed to fix those problems?

    The report included links for Microsoft security bulletins related to each problem but I could not find any software I have installed in order to update it.

    I think it goes without saying that I install all the updates Microsoft update finds daily.

    Thank you for your time.
     
    keiser__, Jan 14, 2021
    #4
Thema:

Fully patched Win10 machine still showing vulnerabilities in IE11 according to Windows...

Loading...
  1. Fully patched Win10 machine still showing vulnerabilities in IE11 according to Windows... - Similar Threads - Fully patched Win10

  2. KB5037570 This patch shows installed successfully but still its detecting as pending patches

    in Windows 10 Gaming
    KB5037570 This patch shows installed successfully but still its detecting as pending patches: Hi,We are facing issues with Microsoft ODBC Driver 17 for SQL Server KB5037570 Even its installed it shows still on pending list on all windows servers.Can we know the reason?...
  3. KB5037570 This patch shows installed successfully but still its detecting as pending patches

    in Windows 10 Software and Apps
    KB5037570 This patch shows installed successfully but still its detecting as pending patches: Hi,We are facing issues with Microsoft ODBC Driver 17 for SQL Server KB5037570 Even its installed it shows still on pending list on all windows servers.Can we know the reason?...
  4. KB5037570 This patch shows installed successfully but still its detecting as pending patches

    in Windows 10 Installation and Upgrade
    KB5037570 This patch shows installed successfully but still its detecting as pending patches: Hi,We are facing issues with Microsoft ODBC Driver 17 for SQL Server KB5037570 Even its installed it shows still on pending list on all windows servers.Can we know the reason?...
  5. Windows not fully posting? Win10

    in Windows 10 Gaming
    Windows not fully posting? Win10: When I turn on my PC windows is not properly posting, I can not access the start menu or any feature through the windows user interface ie, if I click on the speaker on the right of the tasks bar the output audio options and volume controller do not pop outIf I use task...
  6. Windows not fully posting? Win10

    in Windows 10 Software and Apps
    Windows not fully posting? Win10: When I turn on my PC windows is not properly posting, I can not access the start menu or any feature through the windows user interface ie, if I click on the speaker on the right of the tasks bar the output audio options and volume controller do not pop outIf I use task...
  7. Windows not fully posting? Win10

    in Windows 10 Installation and Upgrade
    Windows not fully posting? Win10: When I turn on my PC windows is not properly posting, I can not access the start menu or any feature through the windows user interface ie, if I click on the speaker on the right of the tasks bar the output audio options and volume controller do not pop outIf I use task...
  8. Active X Vulnerability Patch - Where is it?

    in Windows 10 Installation and Upgrade
    Active X Vulnerability Patch - Where is it?: For the Active X vulnerability, on the advisory website you state there's is a patch / upgrade released, without a download link - see https://msrc.microsoft.com/update-guide. Where is the patch? Office is badly affected. Are you guys doing this on purpose, telling there's a...
  9. How to confirm if patches for vulnerabilities are applied on PCs

    in AntiVirus, Firewalls and System Security
    How to confirm if patches for vulnerabilities are applied on PCs: Hi there, Microsoft provides us with security patches. I can see them on the list when I navigate to Control Panel -> Uninstall a program -> View installed updates. However, there are some of them which I cannot see on the list. For example, "Security update for the...
  10. Still vulnerable to WannaCry

    in AntiVirus, Firewalls and System Security
    Still vulnerable to WannaCry: I am currently on Windows 10 N version 1803 (OS Build 17134.191) I've run the windows updater and installed all updates that were offered, but when using the EternalBlues tool that checks for vulnerabilities it still shows that I am vulnerable. Is there a specific patch that...