Tuesday, July 14, 2020

Microsoft July 2020 Security Updates



The Microsoft July security updates have been released and consist of 123 CVEs.  Of these 123 CVEs, 18 are rated Critical and 105 are rated Important in severity.  None are listed as being under attack at the time of release.

The Windows 10 Release Notes include the following new information:
1.  IMPORTANT Starting in July 2020, we will resume non-security releases for Windows 10 and Windows Server, version 1809 and later. There is no change to the cumulative monthly security updates (also referred to as the "B" release or Update Tuesday release). For more information, see the blog post Resuming optional Windows 10 and Windows Server non-security monthly updates 

2.  IMPORTANT Starting in July 2020, all Windows Updates will disable the RemoteFX vGPU feature because of a security vulnerability. For more information about the vulnerability, see CVE-2020-1036 and KB4570006. Once this feature is disabled, attempts to start virtual machines (VMs) will fail, and messages such as the following will appear:
  • “The virtual machine cannot be started because all the RemoteFX-capable GPUs are disabled in Hyper-V Manager.”
  • “The virtual machine cannot be started because the server has insufficient GPU resources.”
If you re-enable RemoteFX vGPU, a message similar to the following will appear:

The updates apply to the following: Microsoft Windows, Microsoft Edge (EdgeHTML-based), Microsoft Edge (Chromium-based) in IE Mode, Microsoft ChakraCore, Internet Explorer, Microsoft Office and Microsoft Office Services and Web Apps, Windows Defender, Skype for Business, Visual Studio, Microsoft OneDrive, Open Source Software, .NET Framework and Azure DevOps. 
 
KB Article Applies To
4558998 Windows 10 Version 1809, Windows Server 2019
4565483 Windows 10, version 1903, Windows Server version 1903, Windows 10, version 1909, Windows Server version 1909
4565511 Windows 10, version 1607, Windows Server 2016
4565524 Windows 7, Windows Server 2008 R2 (Monthly Rollup)
4565529 Windows Server 2008 (Security-only update)
4565535 Windows Server 2012 (Security-only update)
4565536 Windows Server 2008 (Monthly Rollup)
4565537 Windows Server 2012 (Monthly Rollup)
4565539 Windows 7, Windows Server 2008 R2 (Security-only update)
4565540 Windows 8.1, Windows Server 2012 R2 (Security-only update)
4565541 Windows 8.1, Windows Server 2012 R2 (Monthly Rollup)

Recommended Reading:  

See Dustin Childs review and analysis in Zero Day Initiative — The July Security Update Review.

For more information about the updates released today, see https://portal.msrc.microsoft.com/en-us/security-guidance/summary.  Updates can be sorted by OS from the search box. Information about the update for Windows 10 is available at Windows 10 Update history.

Additional Update Notes:

  • Adobe Flash Player -- For Windows Server 2012, Windows 8.1, Windows Server 2012 R2, Windows RT 8.1 and Windows 10, Adobe Flash Player is now a security bulletin rather than a security advisory and is included with the updates as identified above. Note, however, that there are no Adobe Flash Player security updates for Active X.
  • MSRT -- The Malicious Software Removal Tool is now run on a quarterly basis rather than monthly.  See Remove specific prevalent malware with Windows Malicious Software Removal Tool.
  • Servicing Stack Updates -- A list of the latest servicing stack updates for each operating system can be found in ADV990001. This list will be updated whenever a new servicing stack update is released. It is important to install the latest servicing stack update. Learn more about SSU's in Servicing Stack Updates (SSU)
  • Windows 10 updates are cumulative. The monthly security release includes all security fixes for vulnerabilities that affect Windows 10, in addition to non-security updates. The updates are also available via the Microsoft Update Catalog.
  • For information on lifecycle and support dates for Windows 10 operating systems, please see Windows Lifecycle Facts Sheet.
  • Windows Update History:

References


Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...





No comments: