Microsoft CredSSP vulnerability updates

Microsoft issued new security guidance on the Credential Security Support Provider protocol (CredSSP) vulnerability (CVE-2018-0886) that could allow remote code execution. As part of the updates, Microsoft plans to soon prevent un-patched RDP clients (that uses CredSSP) from authenticating to Windows.

Continue Reading Microsoft CredSSP vulnerability updates

Microsoft March 2018 patch updates

Microsoft issued March 2018 Security Updates that includes 75 vulnerability fixes, 15 of them rated critical. The updates address multiple Microsoft products to include Windows, Internet Explorer, Edge, Exchange, Office, Office Services and Web Apps, ChakraCore, PowerShell and Adobe Flash.

Continue Reading Microsoft March 2018 patch updates

Microsoft February 2018 Patch Updates

Microsoft issued February 2018 Security Updates that includes more than 50 fixes, 14 of them critical. The updates address multiple Microsoft products to include Windows, Internet Explorer, Edge, Office, Office Services and Web Apps, ChakraCore and Adobe Flash.

Continue Reading Microsoft February 2018 Patch Updates

Intel issues new Spectre/Meltdown patch guidance

Intel said the root cause of the reboot issues have been identified. To that end, the company said customers and partners should not install its current versions of Spectre/Meltdown patches rolled out earlier this month as they "may introduce higher than expected reboots and other unpredictable system behavior."

Continue Reading Intel issues new Spectre/Meltdown patch guidance

Oracle Critical Patch Update Advisory for January 2018

Oracle has released its Critical Patch Update Advisory for January 2018. The update includes 237 new security fixes for multiple Oracle products to include Spectre (CVE-2017-5753, CVE-2017-5715) and Meltdown (CVE-2017-5754) Intel processor vulnerabilities.

Continue Reading Oracle Critical Patch Update Advisory for January 2018