-
December Patch Tuesday is out
Full coverage in Computerworld Woody on Windows.
As usual, Martin Brinkmann has an excellent detailed list on ghacks.net:
- Windows 7: 2 vulnerabilities, all rated important (which means that they aren’t, really)
- Windows 8.1: 2 vulnerabilities, all rated important
- Windows 10 version 1607: 3 vulnerabilities, all rated important
- Windows 10 version 1703: 3 vulnerabilities, all rated important
- Windows 10 version 1709: 3 vulnerabilities, all rated important
Yes, that means there are no “critical” updates for Windows.
IE and Edge aren’t so lucky — 9 and 12 critical updates, respectively – but then again, you don’t use IE or Edge, do you?
Office patches are available KB article 4055454. One for Office 2007, three for Office 2010, and the usual bunch for Office 2013 and 2016. Looks like they have changed the format on that page.
Reminder: We’re at MS-DEFCON 2. Wait for the cannon fodder to fod. Or do they fud? At any rate, there’s absolutely NO REASON to install any of the updates right now.
I’ll keep you posted, of course.
UPDATES:
PKCano reports that the MSRT is checked on a Win7 machine today. I can confirm on my “Group A” VM.
Big update: All of the Office security patches apparently disable DDE. https://www.askwoody.com/forums/topic/december-patch-tuesday-is-out/#post-151624