Daily Bulletin

Men's Weekly

.

November 2020 Patch Commentary



Microsoft has released updates resolving a total of 112 unique common vulnerabilities and exposures (CVEs) this month. This puts us back up over the 110 CVE threshold. In October Microsoft did not have an update for the browsers and there was a noticeable dip in the total number of CVEs addressed. The updates this month affect the Windows Operating System, Office and Office 365, Internet Explorer, Edge, Edge Chromium, Microsoft Exchange Server, Microsoft Dynamics, Azure Sphere, Windows Defender, Microsoft Teams, Azure SDK, DevOps, ChakraCore and Visual Studio.

One vulnerability has known exploits occurring in the wild already. CVE-2020-17087 is an Elevation of Privilege vulnerability in the Windows Kernel Cryptography Driver, which allows an attacker to elevate their privileges on the system. The vulnerability affects Extended Security Update (ESU) Win 7 and Server 2008 up to the latest Windows 10 20H2 versions. While the vulnerability is only rated as Important by Microsoft, it is a zero-day vulnerability and has been publicly disclosed. This means attackers have already been detected using it in the wild and information on how to exploit it has been distributed publicly, allowing additional threat actors easy access to reproduce this exploit. CVE-2020-17087 was discovered by Google researchers as being exploited in tandem with a Google Chrome flaw (CVE-2020-15999), for which an update was made available on October 20. The two vulnerabilities should be resolved as soon as possible.

Microsoft released Windows 10 20H2 on October 21. While it is light in new features, it includes a couple of nice additions. This release brings full integration of Edge Chromium, improved task bar, better refresh rates for gaming monitors (Yay!), and a slew of fixes to the previous major branch update 2004. It’s important to note how the servicing timelines for Windows 10 branch updates play out. The H1 release is the larger “New Features” release and the H2 release is meant to provide stabilization. So, 2004 had a larger set of new features introduced, but an 18-month lifecycle from release date. 20H2 focused on stabilizing what 2004 introduced and adding a smaller set of enhancements but is meant to be the stable branch for Enterprise, Education, and IoT Enterprise editions with a 30-month lifecycle.

There are a number of Service Stack Updates this month, but the good news is that as of Windows 10 20H2 they are combining the Servicing Stack Update (SSU) with the monthly cumulative update rollup to simplify the process of updating. You would need to enable your 2004 to turn on the 20H2 update or deploy the 20H2 branch upgrade to earlier Win 10 versions, but once you do it will be smoother sailing from there on.

On the third party updates front, today was a little light, but you will want to be sure to account for some very important recent activity.

Oct 20: Google Chrome 86.0.4240.111 resolves 5 CVEs including CVE-2020-15999 (zero-day)

Nov 2: Google Chrome 86.0.4240.183 resolves 10 CVEs including CVE-2020-16009 (zero-day)

Nov 3: Adobe Acrobat and Reader APSB20-67 resolves 14 CVEs

Nov 9: Mozilla Firefox 82.0.3 and ESR 78.4.1 resolving 1 CVE (discovered in Tianfu Cup 2020 International Cybersecurity Contest)

Nov 10: Google Chrome for Android 86.0.4240.185 includes 6 CVEs including CVE-2020-16010 (zero-day)


More Articles ...

  1. Using the Advantages of Modern E-Signing Programs with SignNow
  2. Why Should You Invest In A VPN For Netflix In China?
  3. Selecting a Laptop for Email and Work
  4. Here's Everything You Need To Know About Distribution Boards
  5. The Role of Robotic Process Automation (RPA) in Finance during COVID-19
  6. NBN Bundle Plans to Satisfy Your Appetite for Unlimited Data
  7. How to keep your devices protected while working remotely with kids
  8. The best gaming developers in the industry you don’t want to miss
  9. Understanding the Importance of Dust Suppression Systems
  10. Privacy Tips When Answering Calls
  11. Web Design Tips to Create an Online Store That Ranks Well
  12. 7 Apps College Students Shouldn’t Live Without
  13. The Key Steps Involved to Ensure Enterprise Database Security
  14. Everything You Need to Know About Hydraulic Systems
  15. 6G The Pioneers’ Choice
  16. Can New Video Games Outperform Good Old Classics?
  17. 6 Types Of Refrigerators You Will Need In Your Food Service Operation
  18. What Is a Certificate of Compliance for Electrical Work?
  19. Factors to consider when choosing a mobile phone operator
  20. New ad format promises a brand-safe and powerful new way to reach consumers via video games
  21. Benefits Of Custom Van Shelving On Your Vehicle
  22. 5 Ways To Use Pop Ups On Your Website Without Causing Annoyance
  23. Robotics for Beginners: What Is Arduino?
  24. Choosing The Best Power Supply For Your PC
  25. Most Useful Tools To Have In Garage
  26. 5 Ways Laser Cutting Is Used in Manufacturing Industries
  27. The Ultimate Guide for Tarps
  28. Role of Forensic Engineering in Structural Applications
  29. What are the Benefits of Fibre Optic Cabling?
  30. Everything You Need to Know About Fire Safety in Mines
  31. Mastering Microsoft: How To Get the Most Out Of Office 365
  32. Eight Types Of IT Managed Services Offered By Professionals
  33. Best Printers and Copiers in Australia
  34. Revolutionary App for having glasses prescription at home
  35. Top Tools and Tricks for Computer Data Backup and Recovery
  36. Your Key To The Ultimate Concrete Sealer
  37. What To Look For In A Pet Carpet Cleaner
  38. How To Repair iPhone in Sydney - The Easy Way
  39. Top 8 Benefits Of SEO Training Course
  40. Kaspersky supports healthcare institutions amid COVID-19 pandemic with free full featured product licenses for six months
  41. How to get printer servicing in Melbourne
  42. What Is the Purpose of a High Voltage Test?
  43. Some Of The Best And Useful Information About Story Ads On Instagram
  44. When buying an e-scooter? Consider these factors for right purchase.
  45. 5 video conferencing tips and tricks you need to know
  46. Outdoor Lighting: Its Importance and Benefits
  47. 5 Tips On How To Operate A Forklift Safely
  48. What Are The Advantages Of Polarized Sunglasses?
  49. Why Do I Have No Electricity
  50. App expert: Covidsafe app discriminates against those who most need it

Business News

Workplace Health Checks: A Smart Investment for Small Business Success

Running a small business means every team member counts and when poor health leads to absenteeism or low energy, productivity and profits take a hit. Lost workdays, rising healthcare costs, and staff ...

Daily Bulletin - avatar Daily Bulletin

Rising Demand: Why Melbourne Needs More Electricians Now

Melbourne is running on change. Rooftops are filling with solar, carports are getting charge points, and older switchboards are being rebuilt so homes and shops can carry smarter, heavier loads. If yo...

Daily Bulletin - avatar Daily Bulletin

What Designers Really Think About Your Current Marketing Collateral

Key Takeaways: Designers notice structure, typography, and colour choices before the content itself Consistency across all collateral strengthens brand recognition and builds trust Overly bu...

Daily Bulletin - avatar Daily Bulletin

LayBy Deals