-
May updates for Apple and Microsoft
Yesterday Apple released several updates for Safari, iOS 17.5, iOS 16.7.8, Sonoma 14.5. Ventura 13.6.7, Monterey 12.7.5, WatchOS 10.5, tvOS17.5. On May 8, they also released iTunes 12.13.2 for Windows. Apple has backported a fix for CVE-2024-23296, a critical security flaw in the RTKit real-time operating system, to older iOS, iPadOS, and macOS versions. The #vulnerability allows attackers to bypass kernel memory protections. The updates include anti-tracking feature.
Remember – now is not the time to be installing Windows updates. Before I’d install Apple updates, ensure you have a backup.
May updates for Windows 11 and Windows 10 do include a fix for the corporate vpn bug – This update addresses a known issue that might cause your VPN connection to fail. This occurs after you install the update dated April 9, 2024, or later.
Note that there are .NET updates released but at this time it doesn’t appear there are new security components in the releases (for example). Thus I’ll be monitoring for issues but may not end up recommending installation as they are in my “skip it” category.
.NET 6 does NOT have a new security fix (the KB is wrong) – KB5038350
.NET 7 and .NET 8 have the security fixes see KB5038351 and KB5038352
If you are patching servers, the May updates include the fixes for the NTLM authentication traffic.
For consumers, remember this is the time to ensure your backups are working and properly running. We now wait to see for side effects and test patches on spare machines.
Links for information — Zeroday blog from Dustin Childs