Windows 10: Microsoft's Patch Tuesday August update fixes 74 flaws

Discus and support Microsoft's Patch Tuesday August update fixes 74 flaws in Windows 10 News to solve the problem; Microsoft has patched 74 flaws in its software as part of the company's Patch Tuesday upgrades for August 2023. Last month's update included 132... Discussion in 'Windows 10 News' started by GHacks, Aug 10, 2023.

  1. GHacks
    GHacks New Member

    Microsoft's Patch Tuesday August update fixes 74 flaws


    Microsoft has patched 74 flaws in its software as part of the company's Patch Tuesday upgrades for August 2023. Last month's update included 132 vulnerabilities, which seems like progress.

    On August Patch Tuesday, Microsoft published 74 new CVEs, six of which were classified critical, and one zero-day vulnerability affecting.NET and Visual Studio. CVE-2023-20593 is a vulnerability that exists outside of the Microsoft product line and is related to the Zenbleed hole in specific AMD processors, requiring administrators to apply a microcode patch or BIOS update on vulnerable computers.

    Microsoft's Patch Tuesday August update fixes 74 flaws windows-11-scaled.jpg
    Microsoft Windows
    30 Edge flaws have been fixed


    In addition, Microsoft fixed 30 bugs in its Chromium-based Edge browser since last month's Patch Tuesday edition, as well as one side-channel weakness affecting certain AMD processor types (CVE-2023-20569 or Inception). According to Microsoft, downloading the new version "stops the attack chain," which led to the remote code execution flaw.

    ADV230003 refers to a previously reported security flaw known as CVE-2023-36884, a remote code execution vulnerability in Office and Windows HTML that has been actively exploited by the Russia-linked RomCom threat actor in attacks against Ukraine as well as pro-Ukraine targets in Eastern Europe and North America.


    Windows 11 KB5029263: What's new​


    CVE-2023-38180, a.NET and Visual Studio denial-of-service vulnerability with a CVSS score of 7.5, is the August Patch Tuesday zero-day. Microsoft's CVE notes suggested the existence of proof-of-concept code. Because an attacker does not require privileges to activate the vulnerability, a threat actor with a presence in the organization's infrastructure can start an assault more easily.

    Administrators must patch Microsoft Visual Studio 2022, .NET 7.0, .NET 6.0, and ASP.NET Core 2.1, which might take considerable time if a thorough patch management system is not in place.

    Patches are also included for five privilege escalation flaws in the Windows Kernel (CVE-2023-35359, CVE-2023-35380, CVE-2023-35382, CVE-2023-35386, and CVE-2023-38154, CVSS scores: 7.8) that could be exploited by a threat actor with local access to the target machine to gain SYSTEM privileges.

    Thank you for being a Ghacks reader. The post Microsoft's Patch Tuesday August update fixes 74 flaws appeared first on gHacks Technology News.

    read more...
     
    GHacks, Aug 10, 2023
    #1

  2. Microsoft's infamous 'Patch Tuesday' addresses seven flaws

    Yesterday, Microsoft patched seven problems with Windows XP SP2. The three updates that were marked "critical"-
    • An update to Windows Internet Explorer 7
    • Windows Media Player patch
    • Visual Studio 2005 fix
    The last four updates marked "important" fix flaws in Outlook Express, the SNMP network management protocol, fix privelage problems, and patch a problem with remote installation services. You can read a full rundown of December's Patch Tuesday here. A recent flaw discovered in Microsoft Word remains unpatched.

    Source: The Register
     
    zekrahminator, Aug 10, 2023
    #2
  3. P4-630 Win User
    Microsoft delays Patch Tuesday as world awaits fix for SMB flaw

    "Yesterday was the second Tuesday of February, and that means it should be Microsoft's Patch Tuesday. It should be a big Patch Tuesday, too. First, there's an in-the-wild zero-day flaw in SMB, Microsoft's file sharing protocol, that at the very least allows systems to be crashed, and the patch should be released today.

    Second, Microsoft is continuing to tune the way updates are delivered to Windows 7, 8.1, Server 2008 R2, Server 2012, and Server 2012 R2. The company started moving to a Windows 10-like cumulative model last year in a bid to ensure that the configurations the company tested (all patches applied, all the time) matched the end-user experience. Each operating system is getting two packages a month: a "Monthly Rollup" and a "Security Only" update.

    The "Monthly Rollup" contains both security fixes and general reliability improvements, and it's a cumulative update, incorporating both the current month's fixes and historic updates. The intent is to make it easier to get a freshly installed system up to date; instead of installing hundreds of individual fixes, the latest Monthly Rollup should do the job.

    The "Security Only" package isn't cumulative, and it skips the general reliability improvements.

    Starting this month, the Security Only package is changing a little. Previously, it contained both operating system and Internet Explorer fixes. Going forward, however, the Security Only package will only contain non-Internet Explorer fixes. A second package, the Cumulative Security Update for Internet Explorer, will apply browser fixes. Like the Monthly Rollup—and unlike the Security Only patch—the Internet Explorer package will be cumulative, containing both new and historic patches. Microsoft says this change is being made to reduce the size of the Security Only package.

    The deployment system is also being refined to ensure that neither the Security Only patch nor the Internet Explorer patch will be installed on machines that have a current Monthly Rollup.

    This is all well and good, except it's not happening. Due to a "last-minute issue," Microsoft has delayed this month's updates, and currently, there's no expected time of arrival. This delay may hint at one of the downsides of the combined patching: in the past, an individual fix might be held back due to a late-breaking problem, but other fixes could still be delivered on time as expected. With everything bundled—and, critically, tested—together, the company may be more reluctant to punt an individual fix to next month.

    Still, if the delay means that Microsoft is avoiding shipping a fix that breaks people's computers, it's probably for the best.
    "

    https://arstechnica.com/information...tch-tuesday-as-world-awaits-fix-for-smb-flaw/
     
    P4-630, Aug 10, 2023
    #3
  4. Microsoft's Patch Tuesday August update fixes 74 flaws

    Sumit-Windows Insider MVP, Aug 10, 2023
    #4
Thema:

Microsoft's Patch Tuesday August update fixes 74 flaws

Loading...
  1. Microsoft's Patch Tuesday August update fixes 74 flaws - Similar Threads - Microsoft's Patch Tuesday

  2. Feb Patch Tuesday fixes, finally

    in Windows 10 Software and Apps
    Feb Patch Tuesday fixes, finally: Tomorrow is the big dayHD performance issueTaskbar and morehttps://www.techadvisor.com/news/windows/windows-11-storage-performance-bug-fix-3812972/ https://answers.microsoft.com/en-us/windows/forum/all/feb-patch-tuesday-fixes-finally/a820ddce-37a5-4865-83d4-8f47e5fe8e36
  3. Patch tuesday Windows Update

    in Windows 10 Gaming
    Patch tuesday Windows Update: After build 22000.282, but patch tuesday, update third build windows 11 22000.278, it is correct? https://answers.microsoft.com/en-us/windows/forum/all/patch-tuesday-windows-update/a9b5e468-8d7b-483f-a3e1-a85b09fdb569
  4. Patch tuesday Windows Update

    in Windows 10 Software and Apps
    Patch tuesday Windows Update: After build 22000.282, but patch tuesday, update third build windows 11 22000.278, it is correct? https://answers.microsoft.com/en-us/windows/forum/all/patch-tuesday-windows-update/a9b5e468-8d7b-483f-a3e1-a85b09fdb569
  5. What is Microsoft Patch Tuesday?

    in Windows 10 News
    What is Microsoft Patch Tuesday?: [ATTACH] [ATTACH]Microsoft Patch Tuesday is an unofficial term for the day when Microsoft rolls out updates to its products including Windows and Office. It’s a schedule that Microsoft has been following since 2003 like clockwork. Like any other software, Windows exposes...
  6. Patch Tuesday

    in Windows 10 Installation and Upgrade
    Patch Tuesday: I update an old win7 system to win10 (1903) a few months ago -- all was working find (a bit slow --- old hardware) until August's (2019) patch day --- I think there were 2 update --- one failed -- KB4512508 -- and when the OS reboot -- it was a nightmare I noticed...
  7. Microsoft pushes out fixes for 17 critical flaws as part of Patch Tuesday updates

    in Windows 10 News
    Microsoft pushes out fixes for 17 critical flaws as part of Patch Tuesday updates: As part of Patch Tuesday Microsoft rolled out updates for all its previous Windows operating system. As is always the case with Patch Tuesday releases, Microsoft aims at pushing out fixes for some critical flaws. With today’s updates Microsoft has fixed not less than 61...
  8. Microsoft fixes vulnerabilities in Windows with latest Patch Tuesday update

    in Windows 10 News
    Microsoft fixes vulnerabilities in Windows with latest Patch Tuesday update: Microsoft yesterday released Patch Tuesday updates for all its versions of Windows operating system with bug fixes and performance improvements. The Redmond Giant has addressed vulnerabilities present in several versions of Windows 10 and as well as the other products. The...
  9. August Patch Tuesday updates for Windows 10

    in Windows 10 Installation and Upgrade
    August Patch Tuesday updates for Windows 10: Microsoft has released Patch Tuesday updates to all of their products. Windows 10 1803 KB4343909 is released for version 1803. The build number is 17134.228 after the update. 32 bit download 64 bit download Windows 10 1709 KB4343897 is released for version 1709....
  10. Microsoft’s Patch Tuesday update now available with fixes

    in Windows 10 News
    Microsoft’s Patch Tuesday update now available with fixes: Microsoft released its new set of Patch Tuesday updates for which is now available for all users. The latest updates comes with fixes for not less than 51 vulnerabilities which effects Windows operating system, Microsoft Edge and Office Suite. Microsoft recommends users to...