Patch Updates – Microsoft Zero- Day, Adobe
Microsoft patches 83 security vulnerabilities, including zer0-day Remote Code Execution Vulnerability (CVE-2021-1647).
The January 2021 security release consists of security updates for the following software:
- Microsoft Windows
- Microsoft Edge (EdgeHTML-based)
- Microsoft Office and Microsoft Office Services and Web Apps
- Microsoft Windows Codecs Library
- Visual Studio
- SQL Server
- Microsoft Malware Protection Engine
- .NET Core
- .NET Repository
- ASP .NET
Please note the following information regarding the security updates:
- CVE-2020-0689 has been re-released. For further information see Security update for Secure Boot DBX: January 12, 2021.
- For information regarding enabling Windows 10, version 1909 features, please see Windows 10, version 1909 delivery options. Note that Windows 10, versions 1903 and 1909 share a common core operating system with an identical set of system files. They will also share the same security update KBs.
- Windows 10 updates are cumulative. The monthly security release includes all security fixes for vulnerabilities that affect
- Windows 10, in addition to non-security updates. The updates are available via the Microsoft Update Catalog.
- For information on lifecycle and support dates for Windows 10 operating systems, please see Windows Lifecycle Facts Sheet.
- A list of the latest servicing stack updates for each operating system can be found in ADV990001. This list will be updated whenever a new servicing stack update is released. It is important to install the latest servicing stack update.
- Updates for Windows RT 8.1 and Microsoft Office RT software are only available via Windows Update.
- In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features.
- Customers running Windows 7, Windows Server 2008 R2, or Windows Server 2008 need to purchase the Extended Security Update to continue receiving security updates. See 4522133 for more information.
Microsoft SQL Elevation of Privilege Vulnerability | CVE-2021-1636
How can an attacker exploit this vulnerability? An authenticated attacker can send data over a network to an affected SQL Server when configured to run an Extended Event session.
Can the security updates be applied to SQL Server instances on Windows Azure (IaaS)?
Yes. SQL Server instances on Windows Azure (IaaS) can be offered the security updates through Microsoft Update, or customers can download the security updates from Microsoft Download Center and apply them manually
Note: If your SQL Server version number is not represented in the table below, your SQL Server version is no longer supported. Please upgrade to the latest Service Pack or SQL Server product in order to apply this and future security updates.
Get list of Microsoft security patches here
How To Update Microsoft Windows?
- Open the Control Panel.
- If you are using Small icons view, click on the Windows Update option.
- If you are using the Category view, click on the System and Security option, then click on the Windows Update option.
- Windows Update will check for any available updates for your computer.
- Turn to automatic updates for future.
Adobe Patches Security Bugs – Update Now!
Security Updates Available for Adobe Bridge | APSB21-07
Adobe has released a security update for Adobe Bridge. This update addresses critical vulnerabilities that could lead to arbitrary code execution in the context of the current user.
Security updates available for Adobe Photoshop | APSB21-01
Adobe has released updates for Photoshop for Windows and macOS. These updates resolve a critical vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
For More Adobe security vulnerabilities fixes check here
Subscribe to HackersOnlineClub via Email