• April updates pour in

    It’s that time again when we look to not only Microsoft but other vendors and whether or not we should patch. As always, I recommend that you hold back, get the lay of the land, see if we are issue free (or not), if the issues from last month have been resolved.

    In the meantime:

    149CVEs this month, we’re patching SQL server so if you have a database you weren’t aware of on your PC you might see an update.

    Looks like another bitlocker/secure boot fix.

    Bottom line this definitely is a hang back and don’t patch immediately month.  Windows 11 has “moments”, Windows 10 adds features to the lock screen.

    Dustin Childs’ zero day blog

    Ghacks blog

    I’ll be giving my take on the driver that prevents Edge browser take overs (hint it’s not as evil as the headlines is trying to make it out to be)

    BE AWARE if you have Bitlocker enabled:

    The April releases includes the following fix

    BitLocker Recovery: Some devices may go into BitLocker recovery. Be sure to retain a copy of your BitLocker recovery key before enabling the mitigations.

    Known Issues

    Firmware Issues: Not all device firmware will successfully update the Secure Boot DB or DBX. In the cases that we are aware of, we have reported the issue to the device manufacturer. See KB5016061: Secure Boot DB and DBX variable update events for details on logged events. Please contact the device manufacturer for firmware updates. If the device is not in support, Microsoft recommends upgrading the device.  (see the KB for the firmware impacted

    I’m still working on the Master Patch List (sorry Tax season combined with having a difficult time tracking down the KB numbers for SQL patches).  Will try to get it out by Friday night.