FYI...
MS Security Updates - July 2017
- https://portal.msrc....curity-guidance
[Total items: 989] [Page: 1/10] - 7/11/2017
MS Security Update Summary
> https://portal.msrc....uidance/summary
Total items: 63 - 7/11/2017
> https://blogs.techne...update-release/
July 11, 2017 - "Today, we released security updates to provide additional protections against malicious attackers..."
Release Notes - July 2017 Security Updates
- https://portal.msrc....dc-000d3a32fc99
July 11, 2017 - "The July security release consists of security updates for the following software:
Internet Explorer
Microsoft Edge
Microsoft Windows
Microsoft Office and Microsoft Office Services and Web Apps
.NET Framework
Adobe Flash Player
Microsoft Exchange Server..."
___
MS Office updates
> https://blogs.techne...update-release/
July 11, 2017 - "... This month, there are -17- security updates and 30 non-security updates. All of the security and non-security updates are listed in KB article 4033107*..."
* - https://support.micr...icrosoft-office
Last Review: Jul 11, 2017 - Rev: 12
"... Microsoft released the following security and nonsecurity updates. These monthly updates are intended to help our customers keep their computers up-to-date. We recommend that you install all updates that apply to you..."
Office 2016, Office 2013, Office 2010, Office 2007
___
Additional information/reference:
- http://www.securityt....com/id/1038848
- http://www.securityt....com/id/1038849
- http://www.securityt....com/id/1038850
- http://www.securityt....com/id/1038851
- http://www.securityt....com/id/1038852
- http://www.securityt....com/id/1038853
- http://www.securityt....com/id/1038854
- http://www.securityt....com/id/1038855
- http://www.securityt....com/id/1038856
- http://www.securityt....com/id/1038857
- http://www.securityt....com/id/1038858
- http://www.securityt....com/id/1038859
- http://www.securityt....com/id/1038860
- http://www.securityt....com/id/1038861
- http://www.securityt....com/id/1038862
- http://www.securityt....com/id/1038863
- http://www.securityt....com/id/1038864
- http://www.securityt....com/id/1038865
- http://www.securityt....com/id/1038866
___
ghacks.net:
- https://www.ghacks.n...y-2017-release/
July 11, 2017 - "... Executive Summary:
Microsoft released security updates for all client and server versions of Windows that the company supports.
All operating systems are affected by critical vulnerabilities.
Security updates have been released for other Microsoft products as well including Microsoft Office, Microsoft Edge, and Internet Explorer.
Windows 10 version 1507 won't receive security updates anymore.
Operating System Distribution:
Windows 7: 22 vulnerabilities of which 2 are rated critical, 19 important, and 1 moderate
Windows 8.1: 24 vulnerabilities of which 2 are rated critical, 21 important, and 1 moderate
Windows RT 8.1: 21 vulnerabilities of which 2 are rated critical, and 21 important
Windows 10 version 1703: 27 vulnerabilities of which 2 are rated critical, 23 important and 1 moderate ..."
(More at the ghacks URL above.)
___
- https://www.thezdi.c...y-update-review
July 11, 2017 - "... 57 security patches impacting Windows, Internet Explorer, Edge, Office, SharePoint, .NET Framework, Exchange, and Hololens... some of these vulns were first disclosed to Microsoft during the most recent Pwn2Own competition back in March... all affected vendors were able to produce patches within 120 days... A few of the CVEs addressed by Microsoft this month deserve some extra attention..."
CVE-2017-8463 | Windows Explorer Remote Code Execution Vulnerability
Security Vulnerability
- https://portal.msrc....y/CVE-2017-8463
7/11/2017
CVE-2017-8584 | HoloLens Remote Code Execution Vulnerability
Security Vulnerability
> https://portal.msrc....y/CVE-2017-8584
7/11/2017
___
Qualys analysis: https://blog.qualys....l-adobe-patches
July 11, 2017 - "Today Microsoft released patches covering 54 vulnerabilities as part of July’s Patch Tuesday, with 26 of them affecting Windows. Patches covering 19 of these vulnerabilities are labeled as Critical, all of which can result in Remote Code execution. According to Microsoft, none of these vulnerabilities are currently being exploited in the wild.
Top priority for patching should go to CVE-2017-8589*, which is a vulnerability in the Windows Search service. This vulnerability can be exploited remotely via SMB to take complete control of a system, and can impact both servers and workstations. The issue affects Windows Server 2016, 2012, 2008 R2, 2008 as well as desktop systems like Windows 10, 7 and 8.1. While this vulnerability can leverage SMB as an attack vector, this is not a vulnerability in SMB itself, and is not related to the recent SMB vulnerabilities leveraged by EternalBlue, WannaCry, and Petya... Today’s release is normal in size, and covers 54 vulnerabilities in Windows, Internet Explorer, Edge, Office, .net Framework, Adobe Flash, and Exchange..."
* https://portal.msrc....y/CVE-2017-8589
.
Edited by AplusWebMaster, 12 July 2017 - 04:19 AM.