Time to Patch

IndependentKrebs

Microsoft Patches ‘Wormable’ Flaw in Windows XP, 7 and Windows 2003

Credit to Author: BrianKrebs| Date: Tue, 14 May 2019 17:11:34 +0000

Microsoft today is taking the unusual step of releasing security updates for unsupported but still widely-used Windows operating systems like XP and Windows 2003, citing the discovery of a “wormable” flaw that the company says could be used to fuel a fast-moving malware threat like the WannaCry ransomware attacks of 2017. The vulnerability (CVE-2019-0709) resides in the “remote desktop services” component built into supported versions of Windows, including Windows 7, Windows Server 2008 R2, and Windows Server 2008. It also is present in computers powered by Windows XP and Windows 2003, operating systems for which Microsoft long ago stopped shipping security updates.

Read More
IndependentKrebs

Patch Tuesday Lowdown, April 2019 Edition

Credit to Author: BrianKrebs| Date: Wed, 10 Apr 2019 00:07:33 +0000

Microsoft today released fifteen software updates to fix more than 70 unique security vulnerabilities in various flavors of its Windows operating systems and supported software, including at least two zero-day bugs. These patches apply to Windows, Internet Explorer (IE) and Edge browsers, Office, Sharepoint and Exchange. Separately, Adobe has issued security updates for Acrobat/Reader and Flash Player.

Read More
IndependentKrebs

Patch Tuesday, March 2019 Edition

Credit to Author: BrianKrebs| Date: Wed, 13 Mar 2019 04:55:28 +0000

Microsoft on Tuesday pushed out software updates to fix more than five dozen security vulnerabilities in its Windows operating systems, Internet Explorer, Edge, Office and Sharepoint. If you (ab)use Microsoft products, it’s time once again to start thinking about getting your patches on. Malware or bad guys can remotely exploit roughly one-quarter of the flaws fixed in today’s patch batch without any help from users.

Read More
IndependentKrebs

Patch Tuesday, February 2019 Edition

Credit to Author: BrianKrebs| Date: Wed, 13 Feb 2019 03:31:36 +0000

Microsoft on Tuesday issued a bevy of patches to correct at least 70 distinct security vulnerabilities in Windows and software designed to interact with various flavors of the operating system. This month’s patch batch tackles some notable threats to enterprises — including multiple flaws that were publicly disclosed prior to Patch Tuesday. It also bundles fixes to quash threats relevant to end users, including critical updates for Adobe Flash Player and Microsoft Office, as well as a zero-day bug in Internet Explorer.

Read More
IndependentKrebs

Patch Tuesday, January 2019 Edition

Credit to Author: BrianKrebs| Date: Wed, 09 Jan 2019 14:46:31 +0000

Microsoft on Tuesday released updates to fix roughly four dozen security issues with its Windows operating systems and related software. All things considered, this first Patch Tuesday of 2019 is fairly mild, bereft as it is of any new Adobe Flash updates or zero-day exploits. But there are a few spicy bits to keep in mind. Read on for the gory details.

Read More
IndependentKrebs

Patch Tuesday, December 2018 Edition

Credit to Author: BrianKrebs| Date: Tue, 11 Dec 2018 21:05:41 +0000

Adobe and Microsoft each released updates today to tackle critical security weaknesses in their software. Microsoft’s December patch batch is relatively light, addressing more than three dozen vulnerabilities in Windows and related applications. Adobe has issued security fixes for its Acrobat and PDF Reader products, and has a patch for yet another zero-day flaw in Flash Player that is already being exploited in the wild.

Read More