It seems that due to the BSOD patches being retracted few weeks back, Microsoft had been working hard to restore the status of these vulnerabilities, especially when some of them are critical. Sure enough, we see a new patch that is suppose to replace the previous patch and I think for those who had not uninstalled the patches according to my post here:
http://blog.winston-avalon.com/2014/08/microsoft-aug-patch-tue-could-cause-bsod.html
You should apply this whether or not you had it uninstalled since this is quite critical in my opinion.
Just use your Windows Update and you should see this patch available now!
Search This Blog
Showing posts with label patch tuesday. Show all posts
Showing posts with label patch tuesday. Show all posts
Friday, August 29, 2014
Tuesday, August 19, 2014
Microsoft Aug Patch Tue Could Cause BSOD
Yes, no joke~! 4 of the suspected Patch Tue updates for Aug 2014 were suspected to cause some users to crash or BSOD. Judging from the descriptions, it will only be a matter of time when the criteria are met. In fact, it is Microsoft who advise users to UNINSTALL these patches ASAP!
Don't worry, let me walk you through this. Hopefully when you are now reading this, your PC has not crashed yet. Then the steps are simpler (I did not say it is simple, just not as complicated).
If your Windows is still alive... Time to uninstall those patches. According to Microsoft:
Open the Programs and Features item in Control Panel, and then click View installed updates. Find and then uninstall any of the following update that are currently installed:
- KB2982791
- KB2970228
- KB2975719
- KB2975331
Well, firstly, not very helpful. The patches are not arranged by KB numbers and the search somehow do not deal with these numbers either.
But luckily, you can still sort them by name and you should be looking for these two:
Security Update for Microsoft Windows (KB2982791)
Update for Microsoft Windows (KB2975719)
Based on the descriptions, it is very likely you will only have one of these:
2975719 August 2014 update rollup for Windows RT 8.1, Windows 8.1, and Windows Server 2012 R2
2975331 August 2014 update rollup for Windows RT, Windows 8, and Windows Server 2012
2975331 August 2014 update rollup for Windows RT, Windows 8, and Windows Server 2012
So you might want to look for the other one instead if you are still on Windows 8.0
So, I guess its perfectly normal to have just one of them. As for the other missing one:
2970228 Update to support the new currency symbol for the Russian ruble in Windows
It sound like I may not have it because I do not have the Russian language installed? Likely.
Well if you are a bit out of luck and had the BSOD, you will have to go into safe mode to save that. The details are on their page at:
I strongly suggest you print that out on a working computer. Or be lazy and just system restore back to the previous month... That will probably work.
Friday, July 12, 2013
Patch Tuesday July 2013
Usually I do not talk much about Patch Tuesday from Microsoft, but this time round, it totals to about 30 or so updates on most system with Windows and Office. I think that is would the mention. Not only that, there are 6 rated CRITICAL and many which does not have full details on what and how it is exploited as Microsoft got the vulnerability in private. Doesn't that worry you? It should. For all you know some of these vulnerabilities had already been used in the wild, so I suggest you roll in these patches as soon as possible. (How about NOW??)
So, what are fixed in this round? Here is a summary of it:
- Kernel driver bug due to TTF (yes, I know your WTF look, why would a TTF font be injected into kernel...?) This allow escalation and there is full source code available.
- Several .Net Framework and Silver patches
- Vulnerability in GDI+. Seriously, I think they will never get this fix since it comes back every time.
- IE. For once, IE 10 is badly hit. Usually most vulnerability would not affect IE 10 (on Win8 especially). Well, this is really the patch you need to install ASAP since IE will be your first point of contact.
- Directshow with GIF files. Makes you think how a simple file format thing like PDF, PNG (oh yes, last month we just had one), DOCX or sort. It does seems to have a trend of attacking file formats nowadays.
- Windows Media Format. WMF. There we have it, just to prove my previous point.
- Windows Defender. It's a path transversal. Well, even the big giants has faults sometimes. But the scary part is Microsoft does patch it... Do you see other AV vendors patching their main program much (I know you get updates, but those are AV signatures, they are different things)?
And other patches involving SD card removal, new camera models, language pack and fonts.
So, you can see its going to be a busy busy week. And whoever is using those exploits will probably be sweating or trying their last strike to make good use of it before you patch your computer.
Subscribe to:
Posts (Atom)
Amazon Gift Cards!
Thanks for viewing!
Copyright © 2008 nemesisv.blogspot.com, All rights reserved.

