Qualys analysis: https://blog.qualys.com/laws-of-vulnerabilities/2017/09/12/september-patch-tuesday-27-critical-vulnerabilities-from-microsoft-plus-critical-adobe-patches
Sep 12, 2017 - "Today Microsoft released a fairly large batch of patches covering 81 vulnerabilities as part of September’s Patch Tuesday update, with 38 of them impacting Windows. Patches covering -27- of these vulnerabilities are labeled as -Critical- and -39- can result in Remote Code Execution (RCE). According to Microsoft, one vulnerability impacting HoloLens has a public exploit.
Top priority for patching should go to CVE-2017-0161, an RCE vulnerability in NetBIOS that impacts both servers and workstations. For users of Microsoft’s DHCP server, priority should also be given to CVE-2017-8686, especially if using failover mode, due to another potential RCE.
Out of the 26 vulnerabilities that are both Critical and RCE, -22- of them impact Microsoft’s browsers. Many of these vulnerabilities involve the Scripting Engine, which can impact both browsers and Microsoft Office, and should be considered for prioritizing for workstation-type systems that use email and access the internet via a browser. Adobe has also released patches covering 5 critical vulnerabilities, 2 of which are for Flash. The other patches are for Adobe ColdFusion and RoboHelp."
ghacks.net: https://www.ghacks.net/2017/09/12/microsoft-security-updates-september-2017-release/
Sep 12, 2017 - "… Executive Summary:
Microsoft released security patches for all versions of Windows. Security updates were also released for Internet Explorer, Microsoft Edge, Microsoft Office, Skype for Business and Lync, Microsoft Exchange Server, Adobe Flash Player, and the .Net Framework.
Operating System Distribution:
- Windows 7: 22 vulnerabilities of which 3 are rated critical, 19 important
- Windows 8.1: 26 vulnerabilities of which 4 are rated critical, 22 important
- Windows 10 version 1703: 25 vulnerabilities of which 2 are rated critical, 23 important
Windows Server products:
- Windows Server 2008 R2: 23 vulnerabilities, of which 3 are rated critical, 20 important
- Windows Server 2012 and 2012 R2: 26 vulnerabilities, of which 4 are rated critical 21 important and 1 moderate
- Windows Server 2016: 28 vulnerabilities of which 2 are rated critical, 26 important
Other Microsoft Products:
- Internet Explorer 11: 7 vulnerabilities, 5 critical, 2 important
- Microsoft Edge: 28 vulnerabilities, 19 critical, 7 important, 2 moderate…"
___
MS Sep 2017 patch issues
> https://www.askwoody.com/
"… Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it."
Some OEM factory images causing devices to black screen
- https://support.microsoft.com/en-us/help/4043345
Last Review: Sep 18, 2017 - Rev: 8 - "After installing a Windows Store application update, some users may experience a black screen on their device for 5-10 minutes upon rebooting the OS.
Cause: Some OEM factory images create incorrect registry keys during image creation. These registry keys conflict with the app readiness service. After 5-10 minutes of black screen the user will regain use of their device. This issue is triggered on every reboot.
Resolution: Microsoft is working on a resolution and will provide an update in an upcoming release…"
___
Email retrieval fails after installing Security Patch for Outlook 2010, 2013 and 2016
- https://www.veritas.com/support/en_US/article.000127958
2017-09-20 - "Problem: Users will not be able to retrieve emails after installing the associated Microsoft Outlook Security patch, listed below, released on September 12, 2017.
KB4011089 for Outlook 2010
KB4011090 for Outlook 2013
KB4011091 for Outlook 2016
When this Microsoft Security patch for Outlook is installed on the client, users are unable to access archived emails.Upon double clicking on the shortcut it will open the shortcut only with the banner: "The item has archived by Enterprise vault. Click here to view the original link"
Outlook will become unresponsive, when clicking on the banner.
Cause: These Microsoft Office security updates have disabled scripts for custom forms. Enterprise Vault's archived item shortcuts are custom forms that require scripting for their retrieval functionality.
>> Note: Outlook clients without this patch are not affected…"
Maintaining Windows 10 security tops list of enterprise challenges
- https://www.helpnetsecurity.com/2017/09/21/maintaining-windows-10-security/
Sep 21, 2017 - "Companies are experiencing significant challenges in their attempts to keep their endpoints secure. Maintaining Windows 10 security topped the list of challenges with over half of respondents to an Adaptiva survey indicating it can take a -month- or -more- for IT teams to execute Windows OS updates, which ultimately leaves systems vulnerable…" (More detail at the helpnetsecurity URL above.)
> https://www.askwoody.com/
Sep 26, 2017 - "… Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it…"
Check to see that MS 'Auto Update' is turned off
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it…
- https://askwoody.com/2017/ms-defcon-2-check-to-see-that-auto-update-is-turned-off/
Oct 10, 2017 - "… a slew of patches waiting, for a dozen different platforms, including all versions of Windows (even RT 8.1!), Office, IE, Skype and more…"