• About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
Tech News, Magazine & Review
  • Home
  • Shop
  • Tech News
    You can replace DLSS with AMD FSR 2.0 in Cyberpunk 2077 with this mod

    You can replace DLSS with AMD FSR 2.0 in Cyberpunk 2077 with this mod

    The Sabrent Rocket 4 Plus Destroyer 2 SSD has up to 64 terabytes of speedy storage

    The Sabrent Rocket 4 Plus Destroyer 2 SSD has up to 64 terabytes of speedy storage

    Stadia

    Stadia code change hints Google is prepping Nvidia GPU support

    Intel Core i9-13900 engineering sample is 20% faster than Alder Lake in new benchmarks

    Intel Core i9-13900 engineering sample is 20% faster than Alder Lake in new benchmarks

    AMD Threadripper Pro 5000 to expand availability to more OEMs, hit retail eventually

    AMD Threadripper Pro 5000 to expand availability to more OEMs, hit retail eventually

    YouTube Music can now recommend songs when you connect to earbuds

    YouTube Music can now recommend songs when you connect to earbuds

    Meta logo on a smartphone

    Meta shuts down social media post tracking tool on Facebook

    TikTok is reportedly on pace to rake in $12 billion this year

    TikTok is reportedly on pace to rake in $12 billion this year

  • Review
    The best instant cameras you can buy right now

    The best instant cameras you can buy right now

    Google’s Pixel 5 was the last of its kind

    Google’s Pixel 5 was the last of its kind

    Starlink RV review: the dawn of space internet to go

    Starlink RV review: the dawn of space internet to go

    Poco F4 GT

    Poco F4 GT

    Toyota bZ4X electric SUV review: mediocre at best

    Toyota bZ4X electric SUV review: mediocre at best

    6 Cores vs. 8 Cores for Gaming: 24 Game Benchmark

    6 Cores vs. 8 Cores for Gaming: 24 Game Benchmark

    Edifier MP230

    Edifier MP230

    Amazon Basics Rechargeable AAA 800mAh

    Amazon Basics Rechargeable AAA 800mAh

  • Gear
    Apple TV Siri Remote hinted in iOS 16 beta

    Apple TV Siri Remote hinted in iOS 16 beta

    amazon echo

    Amazon shows off Alexa’s new in-development ability to mimic anyone dead or alive

    Samsung Pay no longer functioning on smartphones from other manufacturers

    Samsung Pay no longer functioning on smartphones from other manufacturers

    Apple

    Apple’s AR glasses are currently in the design development stage: report

    Meta is working on several VR prototypes that aim to pass the Visual Turing test

    Meta is working on several VR prototypes that aim to pass the Visual Turing test

    Sony's Walkman is making a pricey digital comeback

    Sony’s Walkman is making a pricey digital comeback

  • Gaming
    AMD Engineer Confirms RDNA3 GPU Power Consumption Will Increase - ExtremeTech

    AMD Engineer Confirms RDNA3 GPU Power Consumption Will Increase – ExtremeTech

    Cyberpunk 2077 is getting a board game

    Cyberpunk 2077 is getting a board game

    The best tech and gadget gifts for less than $25

    The best tech and gadget gifts for less than $25

    Games Done Quick’s summer marathon kicks off Sunday, and there’s a lot to look forward to

    Games Done Quick’s summer marathon kicks off Sunday, and there’s a lot to look forward to

    Microsoft Adds a Ton of New Gaming Features to Edge - ExtremeTech

    Microsoft Adds a Ton of New Gaming Features to Edge – ExtremeTech

    Legendary designer Yu Suzuki returns with a wild arcade shooter

    Legendary designer Yu Suzuki returns with a wild arcade shooter

    Amazon Offering Fire TV Stick With a Wireless Game Controller in India to Attract Casual Gamers

    Amazon Offering Fire TV Stick With a Wireless Game Controller in India

    Chris Pratt says his Mario voice is ‘unlike anything you’ve heard’

    Chris Pratt says his Mario voice is ‘unlike anything you’ve heard’

  • Smart Phones
    article thumbnail

    Harber Leather Desk Mat review: a comfortable, desirable Mac accessory | AppleInsider

    Asus ROG Phone 5/5S problems and how to fix them

    Asus ROG Phone 5/5S problems and how to fix them

    article thumbnail

    How to download Xcode faster | AppleInsider

    article thumbnail

    Daily deals June 25: $175 AirPods Pro, $40 Amazon Kindle, $30 OtterBox MagSafe Power Bank, more | AppleInsider

    Apple iPhone logo macro

    Should Apple M2 iPads worry the Pixel Tablet crowd?

    Google Pixel 7

    Pixel 7 Pro prototype reveals some details about second-gen Tensor

    article thumbnail

    13-inch MacBook Pro with M2 processor review: Incremental upgrade and unexciting | AppleInsider

    M2

    How the M2 will shape the next Macs and complete the Apple silicon transition

  • More
    • Apps & Software
    • Computing
    • Security
No Result
View All Result
  • Home
  • Shop
  • Tech News
    You can replace DLSS with AMD FSR 2.0 in Cyberpunk 2077 with this mod

    You can replace DLSS with AMD FSR 2.0 in Cyberpunk 2077 with this mod

    The Sabrent Rocket 4 Plus Destroyer 2 SSD has up to 64 terabytes of speedy storage

    The Sabrent Rocket 4 Plus Destroyer 2 SSD has up to 64 terabytes of speedy storage

    Stadia

    Stadia code change hints Google is prepping Nvidia GPU support

    Intel Core i9-13900 engineering sample is 20% faster than Alder Lake in new benchmarks

    Intel Core i9-13900 engineering sample is 20% faster than Alder Lake in new benchmarks

    AMD Threadripper Pro 5000 to expand availability to more OEMs, hit retail eventually

    AMD Threadripper Pro 5000 to expand availability to more OEMs, hit retail eventually

    YouTube Music can now recommend songs when you connect to earbuds

    YouTube Music can now recommend songs when you connect to earbuds

    Meta logo on a smartphone

    Meta shuts down social media post tracking tool on Facebook

    TikTok is reportedly on pace to rake in $12 billion this year

    TikTok is reportedly on pace to rake in $12 billion this year

  • Review
    The best instant cameras you can buy right now

    The best instant cameras you can buy right now

    Google’s Pixel 5 was the last of its kind

    Google’s Pixel 5 was the last of its kind

    Starlink RV review: the dawn of space internet to go

    Starlink RV review: the dawn of space internet to go

    Poco F4 GT

    Poco F4 GT

    Toyota bZ4X electric SUV review: mediocre at best

    Toyota bZ4X electric SUV review: mediocre at best

    6 Cores vs. 8 Cores for Gaming: 24 Game Benchmark

    6 Cores vs. 8 Cores for Gaming: 24 Game Benchmark

    Edifier MP230

    Edifier MP230

    Amazon Basics Rechargeable AAA 800mAh

    Amazon Basics Rechargeable AAA 800mAh

  • Gear
    Apple TV Siri Remote hinted in iOS 16 beta

    Apple TV Siri Remote hinted in iOS 16 beta

    amazon echo

    Amazon shows off Alexa’s new in-development ability to mimic anyone dead or alive

    Samsung Pay no longer functioning on smartphones from other manufacturers

    Samsung Pay no longer functioning on smartphones from other manufacturers

    Apple

    Apple’s AR glasses are currently in the design development stage: report

    Meta is working on several VR prototypes that aim to pass the Visual Turing test

    Meta is working on several VR prototypes that aim to pass the Visual Turing test

    Sony's Walkman is making a pricey digital comeback

    Sony’s Walkman is making a pricey digital comeback

  • Gaming
    AMD Engineer Confirms RDNA3 GPU Power Consumption Will Increase - ExtremeTech

    AMD Engineer Confirms RDNA3 GPU Power Consumption Will Increase – ExtremeTech

    Cyberpunk 2077 is getting a board game

    Cyberpunk 2077 is getting a board game

    The best tech and gadget gifts for less than $25

    The best tech and gadget gifts for less than $25

    Games Done Quick’s summer marathon kicks off Sunday, and there’s a lot to look forward to

    Games Done Quick’s summer marathon kicks off Sunday, and there’s a lot to look forward to

    Microsoft Adds a Ton of New Gaming Features to Edge - ExtremeTech

    Microsoft Adds a Ton of New Gaming Features to Edge – ExtremeTech

    Legendary designer Yu Suzuki returns with a wild arcade shooter

    Legendary designer Yu Suzuki returns with a wild arcade shooter

    Amazon Offering Fire TV Stick With a Wireless Game Controller in India to Attract Casual Gamers

    Amazon Offering Fire TV Stick With a Wireless Game Controller in India

    Chris Pratt says his Mario voice is ‘unlike anything you’ve heard’

    Chris Pratt says his Mario voice is ‘unlike anything you’ve heard’

  • Smart Phones
    article thumbnail

    Harber Leather Desk Mat review: a comfortable, desirable Mac accessory | AppleInsider

    Asus ROG Phone 5/5S problems and how to fix them

    Asus ROG Phone 5/5S problems and how to fix them

    article thumbnail

    How to download Xcode faster | AppleInsider

    article thumbnail

    Daily deals June 25: $175 AirPods Pro, $40 Amazon Kindle, $30 OtterBox MagSafe Power Bank, more | AppleInsider

    Apple iPhone logo macro

    Should Apple M2 iPads worry the Pixel Tablet crowd?

    Google Pixel 7

    Pixel 7 Pro prototype reveals some details about second-gen Tensor

    article thumbnail

    13-inch MacBook Pro with M2 processor review: Incremental upgrade and unexciting | AppleInsider

    M2

    How the M2 will shape the next Macs and complete the Apple silicon transition

  • More
    • Apps & Software
    • Computing
    • Security
No Result
View All Result
No Result
View All Result
Home Security

Microsoft Patch Tuesday Roundup for October

admin by admin
October 13, 2021
Microsoft Patch Tuesday Roundup for October
Share on FacebookShare on Twitter


October is traditionally the time for tricks and treats, and earlier this month, Microsoft delivered what may be considered a treat by some and a trick by others. After declaring back in 2015 that Windows would be “the last version of Windows,” the company apparently had a change of heart and on October 5 released Windows 11. The new OS started to roll out on that date, but not everyone running Windows 10 has been offered the upgrade via Windows Update. The first machines to get the offer are new devices that meet the hardware requirements (which include a Trusted Platform Module version 2.0 as well as minimum processor, memory, and storage specifications). Then it will roll out to the rest on a phased schedule, from now until the middle of 2022.

The upgrade is free, and if you’re the impatient sort and don’t want to wait, you can use Microsoft’s PC Health Check tool to test your computer’s compatibility. If it passes, you can download the Windows 11 installation assistant and do the upgrade now. That’s what I did with my Surface Pro 7, and you can read about that experience and my first impressions of the new operating system on my personal blog.

Meanwhile, whether you’re running the brand new OS or an older version, keeping your operating systems and applications up to date is a never-ending effort. Toward that end, Microsoft released the following slate of Patch Tuesday security fixes on October 12 — which include fixes for Windows 11. Let’s take a look at this month’s critical and important updates.

Overview

As usual, you can download the Excel spreadsheet from the Microsoft Security Update Guide website for a full list of the October releases. This month’s updates apply to a broad range of Microsoft products, features, and roles, including .NET Core & Visual Studio, Active Directory Federation Services, Console Window Host, HTTP.sys, Microsoft DWM Core Library, Microsoft Dynamics, Microsoft Dynamics 365 Sales, Microsoft Edge (Chromium-based), Microsoft Exchange Server, Microsoft Graphics Component, Microsoft Intune, Microsoft Office Excel, Microsoft Office SharePoint, Microsoft Office Visio, Microsoft Office Word, Microsoft Windows Codecs Library, Rich Text Edit Control, Role: DNS Server, Role: Windows Active Directory Server, Role: Windows AD FS Server, Role: Windows Hyper-V, System Center, Visual Studio, Windows AppContainer, Windows AppX Deployment Service, Windows Bind Filter Driver, Windows Cloud Files Mini Filter Driver, Windows Common Log File System Driver, Windows Desktop Bridge, Windows DirectX, Windows Event Tracing, Windows exFAT File System, Windows Fastfat Driver, Windows Installer, Windows Kernel, Windows MSHTML Platform, Windows Nearby Sharing, Windows Network Address Translation (NAT), Windows Print Spooler Components, Windows Remote Procedure Call Runtime, Windows Storage Spaces Controller, Windows TCP/IP, Windows Text Shaping, and Windows Win32K.

Many of the CVEs that are addressed include mitigations, workarounds, or FAQs that may be relevant to specific cases, so be sure to check those out if you are unable to install the updates due to compatibility or other reasons.

This month’s updates include fixes for more than 70 vulnerabilities across the above products. As usual, in this article, we’ll focus on the critical issues since they pose the greatest threat.

Critical and exploited vulnerabilities

This year has seen an increase in zero-day disclosures and attacks, so we will look first at this month’s zero-day vulnerabilities that have been fixed. This includes four vulnerabilities, the first of which is reported to have been widely exploited in attacks on IT companies, military and defense contractors, and diplomatic entities.

Vulnerability being exploited in the wild

The following vulnerability has been detected as having already been exploited in the wild:

CVE-2021-40449 – Win32k Elevation of Privilege Vulnerability. This is an EoP issue that can be exploited by accessing the target system locally or remotely, or the attacker can rely on user interaction. Exploit in the wild has been detected. It affects currently supported versions of Windows client and server operating systems, including Windows 11. Attack complexity and privileges required are low, and exploit can result in a total loss of confidentiality, integrity, and availability. The attack is being called MysterySnail and attributed to Iron Husky and Chinese Advanced Persistent Threat (APT) activity.

Other zero-day vulnerabilities patched

The following three vulnerabilities were publicly exposed before the release of a fix but have not been detected as exploited in the wild:

  • CVE-2021-40469 – Windows DNS Server Remote Code Execution Vulnerability. This is an RCE issue that is remotely exploitable. Attack complexity is low. Attacker requires administrative privileges. No user interaction is needed. It affects currently supported versions of Windows Server, including the server core installation (not Windows client operating systems). The exploit can result in a total loss of confidentiality, integrity, and availability.
  • CVE-2021-41335 – Windows Kernel Elevation of Privilege Vulnerability. This is an EoP issue that can be exploited by accessing the target system locally or remotely, or the attacker can rely on user interaction. It affects currently supported versions of Windows Server and client, but Windows 11 is not listed. Attack complexity and privileges required are low, and exploit can result in a total loss of confidentiality, integrity, and availability.
  • CVE-2021-41338 – Windows AppContainer Firewall Rules Security Feature Bypass Vulnerability. This is an SFB issue that can be exploited by accessing the target system locally or remotely, or the attacker can rely on user interaction. It affects currently supported versions of Windows Server and client, including Windows 11. Attack complexity and privileges required are low, and exploit can result in a total loss of confidentiality. Integrity and availability are not impacted.

Other critical vulnerabilities patched

The following vulnerabilities this month were also classified as critical but had not been disclosed or exploited prior to patch release:

  • CVE-2021-38672 – Windows Hyper-V Remote Code Execution Vulnerability. This is a critical RCE issue in which the vulnerable component is bound to the network stack, but the attack is limited at the protocol level to a logically adjacent topology. Attack complexity is high, with a successful attack dependent on conditions beyond the attacker’s control, but the attacker requires only low privileges. No user interaction is required. It affects Windows 11 and Windows Server 2022. The exploit can result in a total loss of confidentiality, integrity, and availability.
  • CVE-2021-40461 – Windows Hyper-V Remote Code Execution Vulnerability. This is another critical RCE issue similar to the one above in that the vulnerable component is bound to the network stack, but the attack is limited at the protocol level to a logically adjacent topology. Attack complexity is high, with a successful attack dependent on conditions beyond the attacker’s control, but the attacker requires only low privileges. No user interaction is required. It affects Windows 11 and Windows 10 versions 1809, 1909, 21H1, and 20H2, as well as Windows Server 2022, 2019, and version 2004. The exploit can result in a total loss of confidentiality, integrity, and availability.
  • CVE-2021-40486 – Microsoft Word Remote Code Execution Vulnerability. This is an RCE issue in Word in which the attacker exploits the vulnerability by accessing the target system locally (e.g., keyboard, console), or remotely (e.g., SSH); or the attacker relies on User Interaction by another person to perform actions required to exploit the vulnerability. Attack complexity is low, and no privileges are required. However, user interaction is required. It affects Word 2013/2013 RT, 2016, 2019, Office Web Apps Server 2013, SharePoint Enterprise Server 2013, and 2016. The exploit can result in a total loss of confidentiality, integrity, and availability.

Important and moderate updates

In addition to the critical and zero-day updates listed above, this month’s patches address seventy vulnerabilities that are rated important. These include elevation of privilege, information disclosure, spoofing, and remote code execution issues. You can find the full list in the Security Updates Guide. The following are a few of note:

  • CVE-2021-26427 – Microsoft Exchange Server Remote Code Execution Vulnerability. This is an RCE vulnerability in Microsoft Exchange Server. Attack complexity and required privileges are both low and no user interaction is required. It affects Microsoft Exchange Server 2013, 2016, and 2019. The exploit can result in a total loss of confidentiality, integrity, and availability.
  • CVE-2021-36970 – Windows Print Spooler Spoofing Vulnerability. This is a spoofing vulnerability in the print spooler component of the operating system. Attack complexity is low and no privileges are required. However, user interaction is required. It affects supported versions of both the Windows client and server operating systems. The exploit can result in a total loss of confidentiality, integrity, and availability.

Other updates

KB5006671 – Cumulative security update for Internet Explorer.

KB5006743 – Monthly rollup for Windows 7 and Windows Server 2008 R2

KB5006714 – Monthly rollup for Windows 8.1 and Windows Server 2012 R2

KB5006667 – Update for Windows 10 version 1909.

KB5006670 – Update for Windows 10, version 2004, 20H2, and 21H1.

KB5006674 – Update for Windows 11.

KB5006736 – Monthly rollup for Windows Server 2008.

KB5006739 – Monthly rollup for Windows Server 2012.

KB5006699 – Update for Windows Server 2022.

Applying the updates

Most organizations will deploy Microsoft and third-party software updates automatically to their servers and managed client systems using a patch management system of their choice, such as GFI’s LanGuard. Automated patch management saves time and reduces the risk of botched installations.

Most home users will receive the updates via the Windows Update service that’s built into the operating system.

Microsoft provides direct downloads for those who need to install the updates manually. You can download these from the Microsoft Update Catalog.

Known issues

Before installing updates, you should always research whether there are known issues that could affect your particular machines and configurations before rolling out an update to your production systems. There are a large number of such known issues that impact this month’s updates. A full list of links to the KB articles detailing these issues can be found here in the release notes.

Malicious Software Removal Tool (MSRT) update

The MSRT is used to find and remove malicious software from Windows systems, and its definitions are updated regularly. The updates are normally installed via Windows Update, but if you need to download and install them manually, you’ll find the links for the 32- and 64-bit versions in Remove specific prevalent malware with Windows Malicious Software Removal Tool (KB890830) (microsoft.com)

Third-party releases

In addition to Microsoft’s security updates, October Patch Tuesday brought six security advisories and updates from Adobe, which will be discussed in more detail in this month’s Third Party Patch Roundup at the end of this month.





Source link

admin

admin

Related Posts

Google says attackers worked with ISPs to deploy Hermit spyware on Android and iOS

Google says attackers worked with ISPs to deploy Hermit spyware on Android and iOS

June 25, 2022
Majority of Americans fear some form of cyberwarfare

Why we need to take the threat of cyberwarfare seriously [Q&A]

June 24, 2022
Tips for securing Windows with PowerShell... courtesy of the NSA

Tips for securing Windows with PowerShell… courtesy of the NSA

June 24, 2022
Weekend at Johnny's: McAfee's body remains at morgue one year after his death

Weekend at Johnny’s: McAfee’s body remains at morgue one year after his death

June 23, 2022
Next Post
Apple Magic Mouse 1 Vs 2: What Are The Differences?

Apple Magic Mouse 1 Vs 2: What Are The Differences?

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • Trending
  • Comments
  • Latest
Alienware x17 R2 (2022)

Alienware x17 R2 (2022)

June 2, 2022
Toshiba 65UK3163DB

Toshiba 65UK3163DB

April 18, 2022
article thumbnail

Compared: Amazon Fire 7 2022 vs iPad mini & 10.2-inch iPad | AppleInsider

May 22, 2022
How to deactivate your Twitter account

How to deactivate your Twitter account

April 14, 2022
Intel Arc A770 desktop GPU debuts in the Geekbench database

Intel Arc A770 desktop GPU debuts in the Geekbench database

0
New evidence supporting the existence of the Google Pixel Watch emerges

New evidence supporting the existence of the Google Pixel Watch emerges

0
Microsoft is developing an in-game advertising system for free-to-play games

Microsoft is developing an in-game advertising system for free-to-play games

0
WhatsApp testing ability to hide ‘Last Seen’ status from specific contacts on iOS

WhatsApp testing ability to hide ‘Last Seen’ status from specific contacts on iOS

0
Google says attackers worked with ISPs to deploy Hermit spyware on Android and iOS

Google says attackers worked with ISPs to deploy Hermit spyware on Android and iOS

June 25, 2022
article thumbnail

Harber Leather Desk Mat review: a comfortable, desirable Mac accessory | AppleInsider

June 25, 2022
Asus ROG Phone 5/5S problems and how to fix them

Asus ROG Phone 5/5S problems and how to fix them

June 25, 2022
You can replace DLSS with AMD FSR 2.0 in Cyberpunk 2077 with this mod

You can replace DLSS with AMD FSR 2.0 in Cyberpunk 2077 with this mod

June 25, 2022

Don't Miss.

MagSafe Battery Pack

How to update the MagSafe Battery Pack firmware to unlock 7.5W charging

April 21, 2022
OnePlu's Nord Buds are the best $49 earbuds I've ever tested

OnePlu’s Nord Buds are the best $49 earbuds I’ve ever tested

May 19, 2022
Android 13 will solve a major smart home annoyance

Android 13 will solve a major smart home annoyance

April 26, 2022
Virgin Plus logo on a phone with SIM card

Virgin Plus trims down 3G starter plan options

June 10, 2022

GIZMOZOD

Gizmozod is dedicated to providing you the latest news and other information about the tech world that you just need to know. It publishes news related to various tech fields like smartphones, computing, smart home, automotive, gaming, cybersecurity and so on.

Follow Us

Categories

  • Apps & Software
  • Computing
  • Gaming
  • Gear
  • Review
  • Security
  • Smart Phones
  • Tech News

Recent News

Google says attackers worked with ISPs to deploy Hermit spyware on Android and iOS

Google says attackers worked with ISPs to deploy Hermit spyware on Android and iOS

June 25, 2022
article thumbnail

Harber Leather Desk Mat review: a comfortable, desirable Mac accessory | AppleInsider

June 25, 2022

Join Our Newsletter!


    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions

    gizmozod © 2022| All rights reserved.

    No Result
    View All Result
    • Home
    • Shop
    • Tech News
    • Review
    • Gear
    • Gaming
    • Smart Phones
    • More
      • Apps & Software
      • Computing
      • Security

    gizmozod © 2022| All rights reserved.