-
January security patches are out
The Release Notes are up. A total of 93 separate patches.
SANS Internet Storm Center posted its usual list.
No known exploits.
Weird. The Jan. 3 patches are listed in the Update Summary Guide as Jan. 9.
Holy Guacamole, Bitman. Martin Brinkmann just posted his overview at ghacks.net and it goes on for pages and pages and pages.
There’s some confusion about the Equation Editor vulnerability. You may recall that the original hole, CVE-2017-11882, was patched in November. This new patch, for CVE-2018-0802, takes the nuclear option — it removes Equation Editor from Word. @yuhong2 advises on Twitter that the Eqn Editor EXE turns into 0 bytes, so it’s even dead with WordPad.
UPDATE: It looks like the Equation Editor patch is the only patch in this month’s crop that has known exploits.