FYI...
- https://blogs.techne...update-release/
Sep 12, 2017 - "... we released security updates to provide additional protections against malicious attackers. By default, Windows 10 receives these updates automatically..."
- https://portal.msrc....dd-000d3a32fc99
Sep 12, 2017 - "The September security release consists of security updates for the following software:
Internet Explorer
Microsoft Edge
Microsoft Windows
Microsoft Office and Microsoft Office Services and Web Apps
Adobe Flash Player
Skype for Business and Lync
.NET Framework
Microsoft Exchange Server ..."
> https://portal.msrc....uidance/summary
Total items: 96 - Page: 1/1
___
Sept 2017 Office Update Release
- https://blogs.techne...update-release/
Sep 12, 2017 - "... This month, there are -45- security updates and 30 non-security updates. All of the security and non-security updates are listed in KB article 4040279*.
* https://support.micr...icrosoft-office
Last Review: Sep 12, 2017 - Rev: 9
A new version of Office 2013 Click-To-Run is available: 15.0.4963.1002
A new version of Office 2010 Click-To-Run is available: 14.0.7188.5002"
___
Description of Software Update Services and Windows Server Update Services changes in content for 2017
- https://support.micr...ices-changes-in
Last Review: Sep 12, 2017 - Rev: 125
___
Additional info:
- http://www.securityt....com/id/1039320
- http://www.securityt....com/id/1039322
- http://www.securityt....com/id/1039323
- http://www.securityt....com/id/1039324
- http://www.securityt....com/id/1039325
- http://www.securityt....com/id/1039326
- http://www.securityt....com/id/1039327
- http://www.securityt....com/id/1039328
- http://www.securityt....com/id/1039329
- http://www.securityt....com/id/1039330
- http://www.securityt....com/id/1039331
- http://www.securityt....com/id/1039333
- http://www.securityt....com/id/1039337
- http://www.securityt....com/id/1039338
- http://www.securityt....com/id/1039339
- http://www.securityt....com/id/1039340
- http://www.securityt....com/id/1039341
- http://www.securityt....com/id/1039342
- http://www.securityt....com/id/1039343
- http://www.securityt....com/id/1039344
- http://www.securityt....com/id/1039352
- http://www.securityt....com/id/1039369
___
Qualys analysis: https://blog.qualys....l-adobe-patches
Sep 12, 2017 - "Today Microsoft released a fairly large batch of patches covering 81 vulnerabilities as part of September’s Patch Tuesday update, with 38 of them impacting Windows. Patches covering -27- of these vulnerabilities are labeled as -Critical- and -39- can result in Remote Code Execution (RCE). According to Microsoft, one vulnerability impacting HoloLens has a public exploit.
Top priority for patching should go to CVE-2017-0161, an RCE vulnerability in NetBIOS that impacts both servers and workstations. For users of Microsoft’s DHCP server, priority should also be given to CVE-2017-8686, especially if using failover mode, due to another potential RCE.
Out of the 26 vulnerabilities that are both Critical and RCE, -22- of them impact Microsoft’s browsers. Many of these vulnerabilities involve the Scripting Engine, which can impact both browsers and Microsoft Office, and should be considered for prioritizing for workstation-type systems that use email and access the internet via a browser. Adobe has also released patches covering 5 critical vulnerabilities, 2 of which are for Flash. The other patches are for Adobe ColdFusion and RoboHelp."
ghacks.net: https://www.ghacks.n...r-2017-release/
Sep 12, 2017 - "... Executive Summary:
Microsoft released security patches for all versions of Windows. Security updates were also released for Internet Explorer, Microsoft Edge, Microsoft Office, Skype for Business and Lync, Microsoft Exchange Server, Adobe Flash Player, and the .Net Framework.
Operating System Distribution:
- Windows 7: 22 vulnerabilities of which 3 are rated critical, 19 important
- Windows 8.1: 26 vulnerabilities of which 4 are rated critical, 22 important
- Windows 10 version 1703: 25 vulnerabilities of which 2 are rated critical, 23 important
Windows Server products:
- Windows Server 2008 R2: 23 vulnerabilities, of which 3 are rated critical, 20 important
- Windows Server 2012 and 2012 R2: 26 vulnerabilities, of which 4 are rated critical 21 important and 1 moderate
- Windows Server 2016: 28 vulnerabilities of which 2 are rated critical, 26 important
Other Microsoft Products:
- Internet Explorer 11: 7 vulnerabilities, 5 critical, 2 important
- Microsoft Edge: 28 vulnerabilities, 19 critical, 7 important, 2 moderate..."
___
- https://www.us-cert....ecurity-Updates
Sep 12, 2017
Edited by AplusWebMaster, 16 September 2017 - 07:30 AM.