Windows 10: Microsoft addresses 17 critical vulnerabilities in Tuesday’s Patch update

Discus and support Microsoft addresses 17 critical vulnerabilities in Tuesday’s Patch update in Windows 10 News to solve the problem; Microsoft as part of its Patch Tuesday cycle released new security updates for all its supported versions of Windows. The security updates are part of... Discussion in 'Windows 10 News' started by WinLatest, Jul 11, 2018.

  1. WinLatest New Member

    Microsoft addresses 17 critical vulnerabilities in Tuesday’s Patch update


    Microsoft as part of its Patch Tuesday cycle released new security updates for all its supported versions of Windows. The security updates are part of the July 2018 Patch Tuesday cycle.

    The Redmond Giant has fixed 54 vulnerabilities with the latest Patch Tuesday update. There are 17 such vulnerabilities which the Redmond Giant has termed as critical.

    The 17 vulnerabilities which Microsoft has fixed are pertaining to the company’s browser Internet Explorer and Microsoft Edge. Microsoft requests users to install the 17 critical updates to stay away and protected from any vulnerability since they effect the browsers of all supported versions of Windows.

    Microsoft states: “A security feature bypass vulnerability exists when Microsoft Internet Explorer improperly handles requests involving UNC resources. An attacker who successfully exploited the vulnerability could force the browser to load data that would otherwise be restricted.

    Microsoft confirms that the security flaw found in Internet Explorer makes it easy for an attacker to exploit the vulnerability and force the browser to load restricted data. This security flaw hasn’t been disclosed publicly and hence the company would like the users to download the security updates at the earliest.

    The same vulnerability is also effecting Microsoft Edge browser on systems which have downloaded the Windows 10 April 2018 update. The vulnerability allows the attacker to take full control of the PC and steal important data from the effected PC.

    “In all cases an attacker would have no way to force a user to view the attacker-controlled content. Instead, an attacker would have to convince a user to take action. For example, an attacker could trick a user into clicking a link that takes the user to the attacker’s site,” Microsoft says.

    The Microsoft Edge browser vulnerability has been discovered only for users who have downloaded Windows 10 April 2018 update and doesn’t exist for Microsoft Edge browser on older versions of Windows 10.

    To download the latest Patch Tuesday update, you would need to go to Windows Update section and need to reboot the device to complete the deployment of the fixes.

    The post Microsoft addresses 17 critical vulnerabilities in Tuesday’s Patch update appeared first on Windows Latest

    Weiterlesen...
     
    WinLatest, Jul 11, 2018
    #1

  2. Microsoft's infamous 'Patch Tuesday' addresses seven flaws

    Yesterday, Microsoft patched seven problems with Windows XP SP2. The three updates that were marked "critical"-
    • An update to Windows Internet Explorer 7
    • Windows Media Player patch
    • Visual Studio 2005 fix
    The last four updates marked "important" fix flaws in Outlook Express, the SNMP network management protocol, fix privelage problems, and patch a problem with remote installation services. You can read a full rundown of December's Patch Tuesday here. A recent flaw discovered in Microsoft Word remains unpatched.

    Source: The Register
     
    zekrahminator, Jul 11, 2018
    #2
  3. Microsoft passes 130 security fixes for 2015 with final Patch Tuesday


    Microsoft passes 130 security fixes for 2015 with final Patch Tuesday update
    by Dan Worth

    09 Dec 2015

    Microsoft issues final 2015 Patch Tuesday update

    Microsoft has issued its final Patch Tuesday update of 2015, taking the total number of security fixes for the year to 135. This is well in excess of the 85 issued in 2014.

    The December update contained 12 fixes, eight of which are rated critical while the other four are rated as important.

    The critical fixes relate to key Microsoft products including Internet Explorer, its new Edge browser, the Silverlight video player and issues within Windows, as well as Skype for Business and Lync. The four important fixes all relate to Windows.

    The MS15-124 fix for Internet Explorer is a cumulative update for the browser, fixing several issues. Microsoft said the most severe of these could allow remote code execution if a user visits a specifically crafted web page in IE. The Edge update fixes the same problem.

    “An attacker who successfully exploited the vulnerabilities could gain the same user rights as the current user,” explains Microsoft in its notes.

    Meanwhile, the MS15-128 fix covers similar issues in Microsoft Windows, .NET Framework, Microsoft Office, Skype for Business, Microsoft Lync and Silverlight.

    “The vulnerabilities could allow remote code execution if a user opens a specially crafted document or visits a web page that contains specially crafted embedded fonts," Microsoft's notes explain.

    One other notable fix is MS15-135, which, while only rated as important, is the issue that Qualys CTO Wolfgang Kandek said businesses should focus on first, as it addresses a zero-day vulnerability within the Windows kernel.

    “There is no further information about how widely spread the vulnerability and its exploit are, but it is worth a top spot in our priority list," he said.

    Another fix Kandek said IT admins should focus on is MS15-131, which covers an issue within Microsoft Office and is rated as critical.

    "CVE-2015-6172 is a critical vulnerability in Outlook that is triggered by a maliciously formatted email message," he said.

    "There is no reasonable workaround: Microsoft suggests turning off the preview pane - the digital equivalent of 'Just don’t do it', so patch this vulnerability as soon as possible."

    Kandek also said that while part of the increase in vulnerabilities found and fixed in 2015 can be attributed to the release of new products, such as Windows 10 and its Edge browser, the focus on finding security issues is also growing.

    “The majority of the increase is due to new parts of the Windows ecosystem that are being investigated for the first time, a tendency that shows how much more important computer security has become over the years," he said.

    Patch Tuesday

    Microsoft passes 130 security fixes for 2015 with final Patch Tuesday update - IT News from V3.co.uk
     
    hTconeM9user, Jul 11, 2018
    #3
  4. Microsoft addresses 17 critical vulnerabilities in Tuesday’s Patch update

    Microsoft Releasing Eight Patches Next Week

    November's Patch Tuesday is coming up and it will see Microsoft deliver eight fresh software updates - three rated 'Critical' and five rated 'Important'. These patches will address vulnerabilities found in Windows, Office and Internet Explorer. The updates are set to be released this Tuesday, November 12, at about 10:00 a.m. PST.

    For a bit more info on the patches check out the Advance Notification found here.
     
    Cristian_25H, Jul 11, 2018
    #4
Thema:

Microsoft addresses 17 critical vulnerabilities in Tuesday’s Patch update

Loading...
  1. Microsoft addresses 17 critical vulnerabilities in Tuesday’s Patch update - Similar Threads - Microsoft addresses critical

  2. Missed Patch Tuesday

    in Windows 10 Gaming
    Missed Patch Tuesday: Hello, Have a question about Patch Tuesday, i can't get general answer about it and need advice. So in company for some reason was missed two month Patch Tuesday on endpoints, now need to renew it. Question is: does January Patch Tuesday contains missed month security...
  3. Patch tuesday Windows Update

    in Windows 10 Gaming
    Patch tuesday Windows Update: After build 22000.282, but patch tuesday, update third build windows 11 22000.278, it is correct? https://answers.microsoft.com/en-us/windows/forum/all/patch-tuesday-windows-update/a9b5e468-8d7b-483f-a3e1-a85b09fdb569
  4. Patch tuesday Windows Update

    in Windows 10 Software and Apps
    Patch tuesday Windows Update: After build 22000.282, but patch tuesday, update third build windows 11 22000.278, it is correct? https://answers.microsoft.com/en-us/windows/forum/all/patch-tuesday-windows-update/a9b5e468-8d7b-483f-a3e1-a85b09fdb569
  5. What is Microsoft Patch Tuesday?

    in Windows 10 News
    What is Microsoft Patch Tuesday?: [ATTACH] [ATTACH]Microsoft Patch Tuesday is an unofficial term for the day when Microsoft rolls out updates to its products including Windows and Office. It’s a schedule that Microsoft has been following since 2003 like clockwork. Like any other software, Windows exposes...
  6. Patch Tuesday

    in Windows 10 Installation and Upgrade
    Patch Tuesday: I update an old win7 system to win10 (1903) a few months ago -- all was working find (a bit slow --- old hardware) until August's (2019) patch day --- I think there were 2 update --- one failed -- KB4512508 -- and when the OS reboot -- it was a nightmare I noticed...
  7. Microsoft pushes out fixes for 17 critical flaws as part of Patch Tuesday updates

    in Windows 10 News
    Microsoft pushes out fixes for 17 critical flaws as part of Patch Tuesday updates: As part of Patch Tuesday Microsoft rolled out updates for all its previous Windows operating system. As is always the case with Patch Tuesday releases, Microsoft aims at pushing out fixes for some critical flaws. With today’s updates Microsoft has fixed not less than 61...
  8. Microsoft fixes vulnerabilities in Windows with latest Patch Tuesday update

    in Windows 10 News
    Microsoft fixes vulnerabilities in Windows with latest Patch Tuesday update: Microsoft yesterday released Patch Tuesday updates for all its versions of Windows operating system with bug fixes and performance improvements. The Redmond Giant has addressed vulnerabilities present in several versions of Windows 10 and as well as the other products. The...
  9. Microsoft’s Patch Tuesday update now available with fixes

    in Windows 10 News
    Microsoft’s Patch Tuesday update now available with fixes: Microsoft released its new set of Patch Tuesday updates for which is now available for all users. The latest updates comes with fixes for not less than 51 vulnerabilities which effects Windows operating system, Microsoft Edge and Office Suite. Microsoft recommends users to...
  10. Patch Tuesday KB120677

    in Windows 10 Updates and Activation
    Patch Tuesday KB120677: New cumulative update KB120677 No issues here. Follow this link for further information. https://support.microsoft.com/pt-pt/kb/3120677 31406