Tuesday, January 11, 2022

Microsoft January 2022 Security Updates

       

The Microsoft January 2022 security updates have been released and consist of 96 CVEs.  Of these CVEs, 9 are rated Critical, and 89 are rated Important severity.  At the time of release, six are listed as publicly known but none are listed as under active exploit.

The updates apply to a very long list of products, available here.  Additionally announced in the Release Notes is a new notification system.  See Coming Soon: A Brand-New Notification System!

See the KBs listed at January 2022 Security Updates - Release Notes - Security Update Guide - Microsoft for information regarding known issues with the security updates as well as the CVEs with FAQs, Mitigations and/or Workarounds.


Recommended Reading:   See Dustin Childs review and analysis in Zero Day Initiative -- The January 2022 Security Update Review.

 

Additional Update Notes:

 

References



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...




 

Adobe Acrobat DC and Reader DC Security Updates Released

     

Adobe
Adobe has released security updates for Adobe Acrobat and Reader for Windows and macOS. These updates address multiple critical and moderate vulnerabilities. Successful exploitation could lead to arbitrary code execution, memory leak, application denial of service, security feature bypass and privilege escalation 
 
Release date:  January 11, 2022
Vulnerability identifier: APSB21-104
Platform: Windows and MacOS

Update or Complete Download

Reader DC and Acrobat DC were updated to version 21.011.20039.  Updates should become available via the internal updater or checks can be manually activated by choosing Help/Check for Updates.  Reader DC and other versions are available here: https://get.adobe.com/reader/

Note: UNcheck any pre-checked additional options presented with the update. They are not part of the software update and are completely optional.

References
Home
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Mozilla Firefox Version 96.0 Released with Security Updates

        FirefoxMozilla sent Firefox Version 96.0 to the release channel today.  The update includes eighteen security updates of which nine (9) are rated high, six (6) are rated moderate, and three (3) are rated low.

Firefox ESR was updated to Version 91.5.

High

Moderate

 Low

New

  • We’ve made significant improvements in noise-suppression and auto-gain-control as well as slight improvements in echo-cancellation to provide you with a better overall experience.
  • We’ve also significantly reduced main-thread load.
  • Firefox will now enforce the Cookie Policy: Same-Site=lax by default which provides a solid first line of defense against Cross-Site Request Forgery (CSRF) attacks.

Fixed

  • On macOS, command-clicking links in Gmail now opens them in a new tab as expected.
  • Our newest release fixes an issue where video intermittently drops SSRC.
  • It also fixes an issue where WebRTC downgrades screen sharing resolution to provide you with a clearer browsing experience.
  • Plus, we’ve fixed video quality degradation issues on certain sites.
  • Detached video in fullscreen on macOS has been temporarily disabled to avoid some issues with corruption, brightness changes, missing subtitles and high cpu usage. 

Update: To get the update now, select "Help" from the Firefox menu, then pick "About Firefox."  Mac users need to select "About Firefox" from the Firefox menu. If you do not use the English language version, Fully Localized Versions are available for download.

References