Among today's Patches, here is my personal "patch ranking" by order of urgency:
No strong preferences on the rest. Did anybody else notice that MS14-043 is missing? Full patch summary: https://isc.sans.edu/mspatchdays.html?viewday=2016-04-12 If you don't like the layout, here is the API to make your own: https://isc.sans.edu/api/getmspatchday/2016-04-12 (or if you prefer json https://isc.sans.edu/api/getmspatchday/2016-04-12?json ) --- |
Johannes 4478 Posts ISC Handler Apr 13th 2016 |
Thread locked Subscribe |
Apr 13th 2016 6 years ago |
PLEASE go back to the old version of the patch Tuesday report. That was very much easier to read, and incorporate into my own reports. And why change the 'Replaces MS99-001' field with the KB number? If you want to show this, why not add it rather than replace?
|
Anonymous |
Quote |
Apr 13th 2016 6 years ago |
MS16-047 patches Badlock, so I'd bump that to #2 or 3 on the significance list.
'The SAM and LSAD protocol implementations in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 do not properly establish an RPC channel, which allows man-in-the-middle attackers to perform protocol-downgrade attacks and impersonate users by modifying the client-server data stream, aka "Windows SAM and LSAD Downgrade Vulnerability" or "BADLOCK."' -- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-0128 |
Penth 3 Posts |
Quote |
Apr 13th 2016 6 years ago |
Quote:Did anybody else notice that MS14-043 is missing? Really? MS14-043 was published two years ago.-P Did anybody notice that MS16-045 was originally scheduled for the March 2016 patchday but didn't make it then? |
Anonymous |
Quote |
Apr 13th 2016 6 years ago |
Hello,
Why is M16-049 rated as N/A on client side and Important on Server, if the only affected OS is Windows 10? Shouldn't it be the opposite? Important on client and N/A on Server? |
Anonymous |
Quote |
Apr 13th 2016 6 years ago |
KB3148812 update, a non-security update released last week, cause problems:
"Until further notice, if you have not already installed this update, do not install KB3148812" http://blogs.technet.com/b/wsus/archive/2016/04/22/what-you-need-to-know-about-kb3148812-part-two.aspx |
Anonymous |
Quote |
Apr 25th 2016 6 years ago |
Sign Up for Free or Log In to start participating in the conversation!