Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93098 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

MS Security Updates - July 2017


  • Please log in to reply
3 replies to this topic

#1 AplusWebMaster

AplusWebMaster

    AplusWebMaster

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 11 July 2017 - 11:22 AM

FYI...

MS Security Updates - July 2017

- https://portal.msrc....curity-guidance
[Total items: 989] [Page: 1/10] - 7/11/2017

MS Security Update Summary
> https://portal.msrc....uidance/summary
Total items: 63 - 7/11/2017

> https://blogs.techne...update-release/
July 11, 2017 - "Today, we released security updates to provide additional protections against malicious attackers..."

Release Notes - July 2017 Security Updates
- https://portal.msrc....dc-000d3a32fc99
July 11, 2017 - "The July security release consists of security updates for the following software:
    Internet Explorer
    Microsoft Edge
    Microsoft Windows
    Microsoft Office and Microsoft Office Services and Web Apps
    .NET Framework
    Adobe Flash Player
    Microsoft Exchange Server..."

___

MS Office updates
> https://blogs.techne...update-release/
July 11, 2017 - "... This month, there are -17- security updates and 30 non-security updates. All of the security and non-security updates are listed in KB article 4033107*..."
* - https://support.micr...icrosoft-office
Last Review: Jul 11, 2017 - Rev: 12
"... Microsoft released the following security and nonsecurity updates. These monthly updates are intended to help our customers keep their computers up-to-date. We recommend that you install all updates that apply to you..."
Office 2016, Office 2013, Office 2010, Office 2007
___

Additional information/reference:
- http://www.securityt....com/id/1038848
- http://www.securityt....com/id/1038849
- http://www.securityt....com/id/1038850
- http://www.securityt....com/id/1038851
- http://www.securityt....com/id/1038852
- http://www.securityt....com/id/1038853
- http://www.securityt....com/id/1038854
- http://www.securityt....com/id/1038855
- http://www.securityt....com/id/1038856
- http://www.securityt....com/id/1038857
- http://www.securityt....com/id/1038858
- http://www.securityt....com/id/1038859
- http://www.securityt....com/id/1038860
- http://www.securityt....com/id/1038861
- http://www.securityt....com/id/1038862
- http://www.securityt....com/id/1038863
- http://www.securityt....com/id/1038864
- http://www.securityt....com/id/1038865
- http://www.securityt....com/id/1038866
___

ghacks.net:
- https://www.ghacks.n...y-2017-release/
July 11, 2017 - "... Executive Summary:
 Microsoft released security updates for all client and server versions of Windows that the company supports.
 All operating systems are affected by critical vulnerabilities.
 Security updates have been released for other Microsoft products as well including Microsoft Office, Microsoft Edge, and Internet Explorer.
 Windows 10 version 1507 won't receive security updates anymore.
Operating System Distribution:
 Windows 7: 22 vulnerabilities of which 2 are rated critical, 19 important, and 1 moderate
 Windows 8.1: 24 vulnerabilities of which 2 are rated critical, 21 important, and 1 moderate
 Windows RT 8.1: 21 vulnerabilities of which 2 are rated critical, and 21 important
 Windows 10 version 1703: 27 vulnerabilities of which 2 are rated critical, 23 important and 1 moderate ..."
(More at the ghacks URL above.)
___

- https://www.thezdi.c...y-update-review
July 11, 2017 - "... 57 security patches impacting Windows, Internet Explorer, Edge, Office, SharePoint, .NET Framework, Exchange, and Hololens... some of these vulns were first disclosed to Microsoft during the most recent Pwn2Own competition back in March... all affected vendors were able to produce patches within 120 days... A few of the CVEs addressed by Microsoft this month deserve some extra attention..."

CVE-2017-8463 | Windows Explorer Remote Code Execution Vulnerability
Security Vulnerability
- https://portal.msrc....y/CVE-2017-8463
7/11/2017
CVE-2017-8584 | HoloLens Remote Code Execution Vulnerability
Security Vulnerability
> https://portal.msrc....y/CVE-2017-8584
7/11/2017
___

Qualys analysis: https://blog.qualys....l-adobe-patches
July 11, 2017 - "Today Microsoft released patches covering 54 vulnerabilities as part of July’s Patch Tuesday, with 26 of them affecting Windows. Patches covering 19 of these vulnerabilities are labeled as Critical, all of which can result in Remote Code execution. According to Microsoft, none of these vulnerabilities are currently being exploited in the wild.
Top priority for patching should go to CVE-2017-8589*, which is a vulnerability in the Windows Search service. This vulnerability can be exploited remotely via SMB to take complete control of a system, and can impact both servers and workstations. The issue affects Windows Server 2016, 2012, 2008 R2, 2008 as well as desktop systems like Windows 10, 7 and 8.1. While this vulnerability can leverage SMB as an attack vector, this is not a vulnerability in SMB itself, and is not related to the recent SMB vulnerabilities leveraged by EternalBlue, WannaCry, and Petya... Today’s release is normal in size, and covers 54 vulnerabilities in Windows, Internet Explorer, Edge, Office, .net Framework, Adobe Flash, and Exchange..."
* https://portal.msrc....y/CVE-2017-8589

.


Edited by AplusWebMaster, 12 July 2017 - 04:19 AM.

.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...
.

    Advertisements

Register to Remove


#2 AplusWebMaster

AplusWebMaster

    AplusWebMaster

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 15 July 2017 - 01:05 PM

FYI...

Patch Watch: July’s releases fix June’s Issues
> http://windowssecret...x-junes-issues/
July 13, 2017
"... Status recommendations: Skip — patch not needed; Hold — do not install until its problems are resolved; Wait — hold off temporarily while the patch is tested; Optional — not critical, use if wanted; Install — OK to apply."
___

> https://www.askwoody.com/
"Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it."
 

:ph34r: :ph34r: :ph34r:


Edited by AplusWebMaster, 15 July 2017 - 01:42 PM.

.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...
.


#3 AplusWebMaster

AplusWebMaster

    AplusWebMaster

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 17 July 2017 - 08:43 AM

FYI... MS yanks bad Outlook patches...

Outlook 2010 (KB4011042)
- https://support.micr...-2010-kb4011042
Last Review: Jul 11, 2017 - Rev: 17
"Notice: Update 4011042 for Microsoft Outlook 2010 that was released on July 5, 2017, is not currently available. This article will be updated as soon as the update is available again..."

Outlook 2013 (KB3191849)
- https://support.micr...-2013-kb3191849
Last Review: Jul 11, 2017 - Rev: 19
"Notice: Update 3191849 for Microsoft Outlook 2013 that was released on June 27, 2017, is not currently available. This article will be updated as soon as the update is available again..."

Outlook 2016 (KB3213654)
- https://support.micr...-2016-kb3213654
Last Review: Jul 11, 2017 - Rev: 21
"Notice: Update 3213654 for Microsoft Outlook 2016 that was released on June 30, 2017, is not currently available. This article will be updated as soon as the update is available again..."

... as of July 17, 2017
___

Win7 SP1 and Windows Server 2008 R2 SP1
... 2017 July monthly rollup
- https://support.micr...pdate-kb4025341
Last Review: Jul 14, 2017 - Rev: -40-
___

- https://www.askwoody...3213654-401042/
July 15, 2017
- http://www.computerw...654-401042.html
July 15, 2017 - "... earlier versions of the bad patches-of-patches had a nasty habit of crashing Outlook."
___

Win10: https://blogs.msmvps...ms-another-way/
July 17, 2017 - "Next way to get 1703 on systems – again go back to that download page:
- https://www.microsof...nload/windows10
and use the download tool to make the iso/media. Park the iso on a network share and expand it out.
Next use the command switches noted in this blog post:
https://blogs.techne...-line-switches/
Specifically you want to ensure that you do -not- trigger a 'clean install' but an upgrade."

Tracking known issues with Win10 1703:
> https://techcommunit...1703/td-p/67122
 

:ph34r: :ph34r: :ph34r:


Edited by AplusWebMaster, 20 July 2017 - 06:33 AM.

.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...
.


#4 AplusWebMaster

AplusWebMaster

    AplusWebMaster

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 28 July 2017 - 04:16 AM

FYI...

New updates are available for Outlook
- https://blogs.techne...le-for-outlook/
July 27, 2017 - "We released security updates for Outlook today.  See the following KB articles for more information:
- https://support.micr...us/help/4011052
- https://support.micr...us/help/4011078
- https://support.micr...us/help/2956078
- https://support.micr...us/help/3213643
A new version of Office 2013 Click-To-Run is available: 15.0.4953.1001
A new version of Office 2010 Click-To-Run is available: 14.0.7187.5000"
___

CVE-2017-8572 | Microsoft Office Outlook Information Disclosure Vuln
Security Vulnerability
- https://portal.msrc....y/CVE-2017-8572
07/27/2017

- http://www.securityt....com/id/1039010
CVE Reference: CVE-2017-8572
Jul 27 2017
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): 2007 SP3, 2010 SP2, 2013 SP1, 2013 RT SP1, 2016, 2010 C2R, 2013 C2R, 2016 C2R ...
Impact: A remote user can obtain potentially sensitive information on the target system.
Solution: The vendor has issued a fix...
___

CVE-2017-8663 | Microsoft Office Outlook Memory Corruption Vuln
Security Vulnerability
- https://portal.msrc....y/CVE-2017-8663
07/27/2017

- http://www.securityt....com/id/1039011
CVE Reference: CVE-2017-8663
Jul 27 2017
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): 2007 SP3, 2010 SP2, 2013 SP1, 2013 RT SP1, 2016, 2010 C2R, 2013 C2R, 2016 C2R ...
Impact: A remote user can create a file that, when loaded by the target user, will execute arbitrary code on the target user's system.
Solution: The vendor has issued a fix...
___

CVE-2017-8571 | Microsoft Office Outlook Security Feature Bypass Vuln
Security Vulnerability
- https://portal.msrc....y/CVE-2017-8571
07/27/2017

- http://www.securityt....com/id/1039012
CVE Reference: CVE-2017-8571
Jul 27 2017
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): 2007 SP3, 2010 SP2, 2013 SP1, 2013 RT SP1, 2016, 2010 C2R, 2013 C2R, 2016 C2R ...
Impact: A remote user can create a file that, when loaded and interacted with by the target user, will execute arbitrary commands on the target user's system.
Solution: The vendor has issued a fix...
___

Description of the security update for Outlook 2007
- https://support.micr...07-july-27-2017
Last Review: Jul 27, 2017 - Rev: 15

Description of the security update for Outlook 2010
- https://support.micr...10-july-27-2017
Last Review: Jul 27, 2017 - Rev: 14

Description of the security update for Outlook 2013
- https://support.micr...13-july-27-2017
Last Review: Jul 27, 2017 - Rev: 18

Description of the security update for Outlook 2016
- https://support.micr...16-july-27-2017
Last Review: Jul 27, 2017 - Rev: 15
___

MS Security Update Summary
- https://portal.msrc....uidance/summary
Latest dated: 7/27/2017 - Total items: 68
___

> http://www.computerw...urity-bugs.html
Jul 27, 2017
 

:ph34r: :ph34r: :ph34r:


Edited by AplusWebMaster, 28 July 2017 - 10:49 AM.

.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...
.

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users