Microsoft November 2019 Security Updates

Discussion in 'update alerts' started by NICK ADSL UK, Nov 12, 2019.

Thread Status:
Not open for further replies.
  1. NICK ADSL UK

    NICK ADSL UK Administrator

    Joined:
    May 13, 2003
    Posts:
    9,317
    Location:
    UK
    Release Notes
    November 2019 Security Updates
    Release Date: November 12, 2019


    The November security release consists of security updates for the following software:

    • Microsoft Windows
    • Internet Explorer
    • Microsoft Edge (EdgeHTML-based)
    • ChakraCore
    • Microsoft Office and Microsoft Office Services and Web Apps
    • Open Source Software
    • Secure Boot
    • Microsoft Exchange Server
    • Visual Studio
    • Azure Stack
    Please note the following information regarding the security updates:

    • A list of the latest servicing stack updates for each operating system can be found in ADV990001. This list will be updated whenever a new servicing stack update is released. It is important to install the latest servicing stack update.
    • Windows 10 updates are cumulative. The monthly security release includes all security fixes for vulnerabilities that affect Windows 10, in addition to non-security updates. The updates are available via the Microsoft Update Catalog.
    • Updates for Windows RT 8.1 and Microsoft Office RT software are only available via Windows Update.
    • For information on lifecycle and support dates for Windows 10 operating systems, please see Windows Lifecycle Facts Sheet.
    • In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features.
    • Starting in May 2019, Internet Explorer 11 is available on Windows Server 2012. This configuration is present only in the IE Cumulative package.
    The following CVEs have FAQs with additional information and may include * further steps to take after installing the updates. Please note that this is not a complete list of CVEs for this release.

    Known Issues

    The following KBs contain information about known issues with the security updates. For a complete list of security update KBs, please see 20191112

    KB Article Applies To
    4484113 Microsoft Exchange Server
    4523171 Microsoft Exchange Server
    4523205 Windows 10, version 1809, Windows Server 2019
    4524570 Windows 10, version 1903, Windows Server version 1903
    4525232 Windows 10
    4525236 Windows 10, version 1607, Windows Server 2016
    4525237 Windows 10, version 1803, Windows Server version 1803
    4525241 Windows 10, version 1709
    4525243 Windows 8.1, Windows Server 2012 R2 (Monthly Rollup)
    4525246 Windows Server 2012 (Monthly Rollup)
    4525250 Windows 8.1, Windows Server 2012 R2 (Security-only update)
    4525253 Windows Server 2012 (Security-only update)

    https://portal.msrc.microsoft.com/e...tedetail/164aa83e-499c-e911-a994-000d3a33c573
     
  2. NICK ADSL UK

    NICK ADSL UK Administrator

    Joined:
    May 13, 2003
    Posts:
    9,317
    Location:
    UK
    Title: Microsoft Security Update Releases
    Issued: November 12, 2019
    **************************************************************************************

    Summary
    =======

    The following CVEs and advisory have undergone a major revision increment:

    * CVE-2019-1454
    * ADV190024
    * ADV990001


    Revision Information:
    =====================

    - CVE-2019-1454 | Windows User Profile Service Elevation of Privilege Vulnerability
    - https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2019-1454
    - Version: 1.0
    - Reason for Revision: Information published.
    - Originally posted: November 12, 2019
    - Updated: N/A
    - Aggregate CVE Severity Rating: Important

    - ADV190024 | Microsoft Guidance for Vulnerability in Trusted Platform Module (TPM)
    - https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV190024
    - Version: 1.0
    - Reason for Revision: Information published.
    - Originally posted: November 12, 2019
    - Updated: N/A
    - Aggregate CVE Severity Rating: N/A

    - ADV990001 | Latest Servicing Stack Updates
    - https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV990001
    - Version: 16.0
    - Reason for Revision: A Servicing Stack Update has been released for all supported
    versions of Windows. See the FAQ section for more information.
    - Originally posted: November 13, 2018
    - Updated: November 12, 2019
    - Aggregate CVE Severity Rating: Critical
     
  3. NICK ADSL UK

    NICK ADSL UK Administrator

    Joined:
    May 13, 2003
    Posts:
    9,317
    Location:
    UK
    Title: Microsoft Security Update Releases
    Issued: November 20, 2019
    **************************************************************************************

    Summary
    =======

    The following CVEs have undergone a major revision increment:

    * CVE-2019-1460
    * CVE-2019-1108


    Revision Information:
    =====================

    - CVE-2019-1460 | Outlook for Android Spoofing Vulnerability
    - https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2019-1460
    - Version: 1.0
    - Reason for Revision: Information published.
    - Originally posted: November 19, 2019
    - Updated: N/A
    - Aggregate CVE Severity Rating: Important

    - CVE-2019-1108 | Remote Desktop Protocol Client Information Disclosure Vulnerability
    - https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2019-1108
    - Version: 3.0
    - Reason for Revision: The following updates have been made: 1. Added Microsoft
    Remote Desktop for Mac OS to the Security Updates table because it is affected by
    this vulnerability. Microsoft recommends that customers running Microsoft Remote
    Desktop for Mac OS install the latest security update to be fully protected from
    this vulnerability.
    2. Added Microsoft Remote Desktop for iOS to the Security Updates table because it
    is affected by this vulnerability. Microsoft recommends that customers running
    Microsoft Remote Desktop for iOS install the latest security update to be fully
    protected from this vulnerability. Added an FAQ to explain how to get the update
    for iOS.
    - Originally posted: July 9, 2019
    - Updated: November 19, 2019
    - Aggregate CVE Severity Rating: Important
     
  4. NICK ADSL UK

    NICK ADSL UK Administrator

    Joined:
    May 13, 2003
    Posts:
    9,317
    Location:
    UK
    Title: Microsoft Security Advisory Notification
    Issued: December 3, 2019
    **************************************************************************************

    Security Advisory Released on December 3, 2019
    ======================================================================================

    * Microsoft Security Advisory ADV190026

    - ADV190026 | Microsoft Guidance for cleaning up orphaned keys generated on
    vulnerable TPMs and used for Windows Hello for Business
    - https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV190026
    - Reason for Revision: Information published.
    - Originally posted: December 3, 2019
    - Updated: N/A
    - Version: 1.0
     
Loading...
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.