• Recent
  • Popular
  • Unsolved
  • Categories
  • Tags
  • Chat
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
SysAdmins Zone Logo

July 2023 Patch Tuesday

Scheduled Pinned Locked Moved Patch Tuesdays
patchingupdateswindowsmicrosoft
5 Posts 3 Posters 580 Views
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • tankerkiller125T Offline
    tankerkiller125T Offline
    tankerkiller125 Admin
    wrote on last edited by tankerkiller125
    #1

    It's that time again, yet another patch tuesday, and this one is kind of crazy.

    We have the follow count of vulnerabilities:

    • 37 Remote Code Executition
    • 33 Elevation of Privilege
    • 22 DoS
    • 19 Information Disclosure
    • 13 Security Feature Bypass
    • 7 Spoofing

    Of those vulnerabilities 6 of them are Zero Days:

    • CVE-2023-32046 - Windows MSHTML Elevation of Privilege
    • CVE-2023-32049 - SmartScreen Bypass
    • CVE-2023-36874 - Error Reporting Elevation of Privilege
    • CVE-2023-36884 - Office and Windows HTML Code Execution
    • CVE-2023-35311 - Outlook Preview Pane Security Bypass

    Out of these bugs, the only one that requires admin intervention is CVE-2023-36884, notably you should add the following registry keys (note that this is in .reg file format) IF you do not have the "Block all Office Apps from creating child processes" ASR enabled.

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATION]
    "Excel.exe"=dword:00000001
    "Graph.exe"=dword:00000001
    "MSAccess.exe"=dword:00000001
    "MSPub.exe"=dword:00000001
    "PowerPoint.exe"=dword:00000001
    "Visio.exe"=dword:00000001
    "WinProj.exe"=dword:00000001
    "WinWord.exe"=dword:00000001
    "Wordpad.exe"=dword:00000001
    

    Additionally, Microsoft published a security advisor related to some drivers that were signed being used maliciously after initial compromise. Microsoft has revoked those certificates from the program and blocked them. You can read more about that in ADV230001

    Thanks again Microsoft for keeping all of sysadmins in business and making money 🙂

    For the full list of all the vulnerabilities patched you can go to the release notes

    1 Reply Last reply
    0
  • tankerkiller125T Offline
    tankerkiller125T Offline
    tankerkiller125 Admin
    wrote on last edited by
    #2

    No issues on my Win 11 laptop so far since updating. AD servers are updating later tonight so we'll see how that goes in the morning.

    1 Reply Last reply
    0
  • B Offline
    B Offline
    BillyScott
    wrote on last edited by
    #3

    This is the same patch that will start enforcing that fix in Active Directory right?

    katosK tankerkiller125T 2 Replies Last reply
    0
  • katosK Offline
    katosK Offline
    katos Admin
    replied to BillyScott on last edited by
    #4

    BillyScott that’s enforced in this round of updates if you’re on about the Kerberos signing, yes.

    1 Reply Last reply
    0
  • tankerkiller125T Offline
    tankerkiller125T Offline
    tankerkiller125 Admin
    replied to BillyScott on last edited by
    #5

    BillyScott as katos pointed out yes Kerberos signing is enforced in this round of updates.

    I can also come back after the AD updates last night and say that it had zero impact on our business this morning. So far everything is business as usual.

    1 Reply Last reply
    0

© Copyright 2023, SysAdmins Zone.
Terms of Service | Privacy Policy
  • Login

  • Don't have an account? Register

  • Login or register to search.
  • First post
    Last post
0
  • Recent
  • Popular
  • Unsolved
  • Categories
  • Tags
  • Chat
  • Login

  • Don't have an account? Register

  • Login or register to search.