Windows 10: Microsoft fixes vulnerabilities in Windows with latest Patch Tuesday update

Discus and support Microsoft fixes vulnerabilities in Windows with latest Patch Tuesday update in Windows 10 News to solve the problem; Microsoft yesterday released Patch Tuesday updates for all its versions of Windows operating system with bug fixes and performance improvements. The... Discussion in 'Windows 10 News' started by WinLatest, Aug 15, 2018.

  1. WinLatest New Member

    Microsoft fixes vulnerabilities in Windows with latest Patch Tuesday update


    Microsoft yesterday released Patch Tuesday updates for all its versions of Windows operating system with bug fixes and performance improvements. The Redmond Giant has addressed vulnerabilities present in several versions of Windows 10 and as well as the other products.

    The company released Patch Tuesday update for its previous version April 2018 Update for Windows 10 users. The company fixed a total of 60 security vulnerabilities found in the previous version of the OS.

    The most important security flaw affects Windows shell, which could allow the attacker to run arbitrary code in the context of the current user, only if the vulnerability is exploited.

    “To exploit the vulnerability, an attacker must entice a user to open a specially crafted file. In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and then convincing the user to open the file. In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) that contains a specially crafted file designed to exploit the vulnerability. An attacker would have no way to force a user to visit the website. Instead, an attacker would have to convince a user to click a link and open the specially crafted file,” the company explains.

    Another flaw which is termed as “Scripting Engine Memory Corruption Vulnerability” is a remote code execution vulnerability, it could allow users to execute arbitrary code in the context of the current user.

    This vulnerability affects users who still use Internet Explorer and browser websites with malicious content.

    “In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit the vulnerability through Internet Explorer and then convince a user to view the website. An attacker could also embed an ActiveX control marked “safe for initialization” in an application or Microsoft Office document that hosts the IE rendering engine. The attacker could also take advantage of compromised websites and websites that accept or host user-provided content or advertisements. These websites could contain specially crafted content that could exploit the vulnerability,” the company writes.

    Microsoft has also included fixes to address Intel CPUs vulnerabilities, Adobe Flash Player and as well as the Office vulnerabilities.

    The post Microsoft fixes vulnerabilities in Windows with latest Patch Tuesday update appeared first on Windows Latest

    Weiterlesen...
     
    WinLatest, Aug 15, 2018
    #1

  2. Microsoft passes 130 security fixes for 2015 with final Patch Tuesday


    Microsoft passes 130 security fixes for 2015 with final Patch Tuesday update
    by Dan Worth

    09 Dec 2015

    Microsoft issues final 2015 Patch Tuesday update

    Microsoft has issued its final Patch Tuesday update of 2015, taking the total number of security fixes for the year to 135. This is well in excess of the 85 issued in 2014.

    The December update contained 12 fixes, eight of which are rated critical while the other four are rated as important.

    The critical fixes relate to key Microsoft products including Internet Explorer, its new Edge browser, the Silverlight video player and issues within Windows, as well as Skype for Business and Lync. The four important fixes all relate to Windows.

    The MS15-124 fix for Internet Explorer is a cumulative update for the browser, fixing several issues. Microsoft said the most severe of these could allow remote code execution if a user visits a specifically crafted web page in IE. The Edge update fixes the same problem.

    “An attacker who successfully exploited the vulnerabilities could gain the same user rights as the current user,” explains Microsoft in its notes.

    Meanwhile, the MS15-128 fix covers similar issues in Microsoft Windows, .NET Framework, Microsoft Office, Skype for Business, Microsoft Lync and Silverlight.

    “The vulnerabilities could allow remote code execution if a user opens a specially crafted document or visits a web page that contains specially crafted embedded fonts," Microsoft's notes explain.

    One other notable fix is MS15-135, which, while only rated as important, is the issue that Qualys CTO Wolfgang Kandek said businesses should focus on first, as it addresses a zero-day vulnerability within the Windows kernel.

    “There is no further information about how widely spread the vulnerability and its exploit are, but it is worth a top spot in our priority list," he said.

    Another fix Kandek said IT admins should focus on is MS15-131, which covers an issue within Microsoft Office and is rated as critical.

    "CVE-2015-6172 is a critical vulnerability in Outlook that is triggered by a maliciously formatted email message," he said.

    "There is no reasonable workaround: Microsoft suggests turning off the preview pane - the digital equivalent of 'Just don’t do it', so patch this vulnerability as soon as possible."

    Kandek also said that while part of the increase in vulnerabilities found and fixed in 2015 can be attributed to the release of new products, such as Windows 10 and its Edge browser, the focus on finding security issues is also growing.

    “The majority of the increase is due to new parts of the Windows ecosystem that are being investigated for the first time, a tendency that shows how much more important computer security has become over the years," he said.

    Patch Tuesday

    Microsoft passes 130 security fixes for 2015 with final Patch Tuesday update - IT News from V3.co.uk
     
    hTconeM9user, Sep 24, 2018
    #2
  3. Microsoft's infamous 'Patch Tuesday' addresses seven flaws

    Yesterday, Microsoft patched seven problems with Windows XP SP2. The three updates that were marked "critical"-
    • An update to Windows Internet Explorer 7
    • Windows Media Player patch
    • Visual Studio 2005 fix
    The last four updates marked "important" fix flaws in Outlook Express, the SNMP network management protocol, fix privelage problems, and patch a problem with remote installation services. You can read a full rundown of December's Patch Tuesday here. A recent flaw discovered in Microsoft Word remains unpatched.

    Source: The Register
     
    zekrahminator, Sep 24, 2018
    #3
  4. P4-630 Win User

    Microsoft fixes vulnerabilities in Windows with latest Patch Tuesday update

    Microsoft delays Patch Tuesday as world awaits fix for SMB flaw

    "Yesterday was the second Tuesday of February, and that means it should be Microsoft's Patch Tuesday. It should be a big Patch Tuesday, too. First, there's an in-the-wild zero-day flaw in SMB, Microsoft's file sharing protocol, that at the very least allows systems to be crashed, and the patch should be released today.

    Second, Microsoft is continuing to tune the way updates are delivered to Windows 7, 8.1, Server 2008 R2, Server 2012, and Server 2012 R2. The company started moving to a Windows 10-like cumulative model last year in a bid to ensure that the configurations the company tested (all patches applied, all the time) matched the end-user experience. Each operating system is getting two packages a month: a "Monthly Rollup" and a "Security Only" update.

    The "Monthly Rollup" contains both security fixes and general reliability improvements, and it's a cumulative update, incorporating both the current month's fixes and historic updates. The intent is to make it easier to get a freshly installed system up to date; instead of installing hundreds of individual fixes, the latest Monthly Rollup should do the job.

    The "Security Only" package isn't cumulative, and it skips the general reliability improvements.

    Starting this month, the Security Only package is changing a little. Previously, it contained both operating system and Internet Explorer fixes. Going forward, however, the Security Only package will only contain non-Internet Explorer fixes. A second package, the Cumulative Security Update for Internet Explorer, will apply browser fixes. Like the Monthly Rollup—and unlike the Security Only patch—the Internet Explorer package will be cumulative, containing both new and historic patches. Microsoft says this change is being made to reduce the size of the Security Only package.

    The deployment system is also being refined to ensure that neither the Security Only patch nor the Internet Explorer patch will be installed on machines that have a current Monthly Rollup.

    This is all well and good, except it's not happening. Due to a "last-minute issue," Microsoft has delayed this month's updates, and currently, there's no expected time of arrival. This delay may hint at one of the downsides of the combined patching: in the past, an individual fix might be held back due to a late-breaking problem, but other fixes could still be delivered on time as expected. With everything bundled—and, critically, tested—together, the company may be more reluctant to punt an individual fix to next month.

    Still, if the delay means that Microsoft is avoiding shipping a fix that breaks people's computers, it's probably for the best.
    "

    https://arstechnica.com/information...tch-tuesday-as-world-awaits-fix-for-smb-flaw/
     
    P4-630, Sep 24, 2018
    #4
Thema:

Microsoft fixes vulnerabilities in Windows with latest Patch Tuesday update

Loading...
  1. Microsoft fixes vulnerabilities in Windows with latest Patch Tuesday update - Similar Threads - Microsoft fixes vulnerabilities

  2. Microsoft's Patch Tuesday August update fixes 74 flaws

    in Windows 10 News
    Microsoft's Patch Tuesday August update fixes 74 flaws: Microsoft has patched 74 flaws in its software as part of the company's Patch Tuesday upgrades for August 2023. Last month's update included 132 vulnerabilities, which seems like progress. On August Patch Tuesday, Microsoft published 74 new CVEs, six of which were classified...
  3. Feb Patch Tuesday fixes, finally

    in Windows 10 Gaming
    Feb Patch Tuesday fixes, finally: Tomorrow is the big dayHD performance issueTaskbar and morehttps://www.techadvisor.com/news/windows/windows-11-storage-performance-bug-fix-3812972/ https://answers.microsoft.com/en-us/windows/forum/all/feb-patch-tuesday-fixes-finally/a820ddce-37a5-4865-83d4-8f47e5fe8e36
  4. Feb Patch Tuesday fixes, finally

    in Windows 10 Software and Apps
    Feb Patch Tuesday fixes, finally: Tomorrow is the big dayHD performance issueTaskbar and morehttps://www.techadvisor.com/news/windows/windows-11-storage-performance-bug-fix-3812972/ https://answers.microsoft.com/en-us/windows/forum/all/feb-patch-tuesday-fixes-finally/a820ddce-37a5-4865-83d4-8f47e5fe8e36
  5. Patch tuesday Windows Update

    in Windows 10 Gaming
    Patch tuesday Windows Update: After build 22000.282, but patch tuesday, update third build windows 11 22000.278, it is correct? https://answers.microsoft.com/en-us/windows/forum/all/patch-tuesday-windows-update/a9b5e468-8d7b-483f-a3e1-a85b09fdb569
  6. Patch tuesday Windows Update

    in Windows 10 Software and Apps
    Patch tuesday Windows Update: After build 22000.282, but patch tuesday, update third build windows 11 22000.278, it is correct? https://answers.microsoft.com/en-us/windows/forum/all/patch-tuesday-windows-update/a9b5e468-8d7b-483f-a3e1-a85b09fdb569
  7. What is Microsoft Patch Tuesday?

    in Windows 10 News
    What is Microsoft Patch Tuesday?: [ATTACH] [ATTACH]Microsoft Patch Tuesday is an unofficial term for the day when Microsoft rolls out updates to its products including Windows and Office. It’s a schedule that Microsoft has been following since 2003 like clockwork. Like any other software, Windows exposes...
  8. Patch Tuesday

    in Windows 10 Installation and Upgrade
    Patch Tuesday: I update an old win7 system to win10 (1903) a few months ago -- all was working find (a bit slow --- old hardware) until August's (2019) patch day --- I think there were 2 update --- one failed -- KB4512508 -- and when the OS reboot -- it was a nightmare I noticed...
  9. Microsoft addresses 17 critical vulnerabilities in Tuesday’s Patch update

    in Windows 10 News
    Microsoft addresses 17 critical vulnerabilities in Tuesday’s Patch update: Microsoft as part of its Patch Tuesday cycle released new security updates for all its supported versions of Windows. The security updates are part of the July 2018 Patch Tuesday cycle. The Redmond Giant has fixed 54 vulnerabilities with the latest Patch Tuesday update....
  10. Microsoft’s Patch Tuesday update now available with fixes

    in Windows 10 News
    Microsoft’s Patch Tuesday update now available with fixes: Microsoft released its new set of Patch Tuesday updates for which is now available for all users. The latest updates comes with fixes for not less than 51 vulnerabilities which effects Windows operating system, Microsoft Edge and Office Suite. Microsoft recommends users to...

Users found this page by searching for:

  1. ms15-124

    ,
  2. microsoft 180810-1706