For December, an exceptionally light Patch Tuesday

Over the previous 12 months, we have seen Microsoft make radical enhancements in its browser stability and important constructive modifications to its Home windows replace communication and telemetry methods.  And this month's Patch Tuesday launch brings with it an extremely gentle set of updates — perhaps the fewest variety of updates I've ever seen.There aren't …

For December, an exceptionally light Patch Tuesday

UrbanPLR Ad

Over the previous 12 months, we have seen Microsoft make radical enhancements in its browser stability and important constructive modifications to its Home windows replace communication and telemetry methods.  And this month’s Patch Tuesday launch brings with it an extremely gentle set of updates — perhaps the fewest variety of updates I’ve ever seen.

There aren’t any zero-days, which is a superb end to 2023, although Home windows will get three important updates and Visible Studio would require quick consideration on account of a number of re-releases of previous important software patches.

The group at Readiness has created a useful infographic to stipulate the dangers related to every replace on this final launch of 2023. One word of warning: now we have seen a number of potential updates to older patches (October/November) probably coming down the discharge pipeline from Microsoft. It may be value checking in in the course of the upcoming vacation break to see whether or not there are any out-of-band patches for the Home windows ecosystem.

Recognized points

Every month, Microsoft particulars the recognized points associated to the working system and platforms included in its replace cycle.

  • Microsoft has raised a reporting-related subject with Microsoft Intune and BitLocker. Utilizing the FixedDrivesEncryptionType or SystemDrivesEncryptionType coverage settings within the BitLocker configuration service supplier (CSP) node in cellular gadget administration (MDM) apps may incorrectly present a 65000 error within the “Require Gadget Encryption” setting for some units in your atmosphere. Microsoft continues to be engaged on resolving this subject.
  • Home windows units utilizing multiple monitor may expertise points with desktop icons transferring unexpectedly between screens or see different icon alignment points when making an attempt to make use of Copilot in Home windows. This was raised final month and it seems Microsoft continues to be engaged on the problem.

Although we’re not experiencing printer issues with Patch Tuesday as now we have prior to now, HP Printers at the moment are being displayed on Home windows computer systems, even when HP printers are neither related nor put in. Signs of this may embrace:

  1. Some Home windows 10 and Home windows 11 units are putting in the HP Good app.
  2. Printers are renamed as HP printers no matter their producer. Most are being named because the HP LaserJet M101-M106 mannequin. Printer icons may also be modified.
  3. Double clicking on a printer shows the on-screen error “No duties can be found for this web page.”

Microsoft has confirmed that this isn’t the results of an HP Printer replace and is engaged on a decision.

Main revisions

That is an uncommon month for Microsoft, as there are usually a number of “data solely” revisions to earlier updates. This month, Microsoft has re-published updates for each Microsoft Edge and Microsoft Visible Studio that may require (within the case of Visible Studio, pressing) consideration. I’ve up to date these Browser and Growth sections accordingly.

Mitigations and workarounds

Following the sample set this month, Microsoft broke with custom and has not launched any documentation on present vulnerability mitigations or workarounds.

Testing steering

Every month, the group at Readiness analyses the most recent Patch Tuesday updates and gives detailed, actionable testing steering based mostly on a big software portfolio and an in depth evaluation of the Microsoft patches and their potential influence on the Home windows platforms and software installations.

For this end-of-year replace, now we have not seen any high-risk or important performance modifications for Home windows. Nevertheless, there have been a number of modifications to core performance that may require some consideration, together with:

  • Home windows Networking: Web Connection Sharing (ICS), the Home windows DHCP IP providers supplier has been up to date. We suggest that you just progress the next checks:
    1. Ping native/distant units (embrace Google.com and Bing.com).
    2. Browse the web, with each massive and small file downloads.
    3. Stream music and video.
    4. Run messaging apps (embrace Microsoft Groups).
  • Home windows kernel updates. The Home windows kernel lies on the very core of the Home windows working system and any modifications must be examined with care. That stated, the modifications applied this month have a really low floor space and may current themselves with a easy reboot.
  • SQL Shoppers and OLE: The Microsoft SQL purchasers for each SQL server and OLE have been up to date. We suggest working fundamental SQL instructions to fetch/replace information from each an area and distant server.

You won’t bear in mind Faxing (exhibiting my age right here) however Microsoft has made a minor replace to a single discrete perform name within the MakeCall API perform. In case you are utilizing automated faxes in your workflows or depend on a FAX server comparable to FAXPress, then you will have to carry out a whole take a look at that features sending, receiving, and the administration of current faxes.

Automated testing will assist with these eventualities (particularly a testing platform that gives a “delta” or comparability between builds). Nevertheless, for line of enterprise purposes, getting the applying proprietor (doing UAT) to check and approve the testing outcomes continues to be completely important.

Home windows lifecycle replace

This part contains essential modifications to servicing (and most safety updates) to Home windows desktop and server platforms. There aren’t any main modifications or finish of assist notices for the Home windows or Workplace platforms this month. Nevertheless, Microsoft has printed the top of neighborhood assist for PHP 8.0. For these affected, Microsoft gives just a few steps to help with updating purposes.

Every month, we break down the replace cycle into product households (as outlined by Microsoft) with the next fundamental groupings:

  • Browsers (Microsoft IE and Edge).
  • Microsoft Home windows (each desktop and server).
  • Microsoft Workplace.
  • Microsoft Change Server.
  • Microsoft Growth platforms (NET Core, .NET Core and Chakra Core).
  • Adobe (retired???, perhaps subsequent 12 months).

Browsers

The most important modifications included with this December browser replace lie throughout the Chrome browser elements together with:

These revisions are comparatively minor and mustn’t pose a compatibility downside; add these updates to your commonplace browser patch launch schedule.

Home windows

This month, Microsoft launched three important updates and 22 patches rated essential to the Home windows platform that cowl the next key elements:

  • Home windows Networking, ICS, DHCP and DNS;
  • Home windows Kernel and Win32K drivers;
  • Home windows Telephony Server (a single API replace);
  • Microsoft Bluetooth drivers.

Your testing and deployment focus must be on guaranteeing that  goal methods are working as anticipated with this month’s networking updates. At any time when Microsoft updates the Kernel (far too typically), care should be taken with exterior units that depend on system degree drivers. A superb couple of reboots this month ought to do the trick.

Add this Home windows replace to your commonplace launch schedule.

Microsoft Workplace

Microsoft launched three comparatively minor updates to Microsoft Phrase. These patches handle lowe- threat vulnerabilities, have a low testing profile, and are rated as essential. Add these Workplace updates to your commonplace launch schedule.

Microsoft Change Server

Fortunate for us — and for these working over the Christmas break — there aren’t any Microsoft Change Server updates.

Microsoft growth platforms

There have been no new growth platforms (.NET or Microsoft Visible Studio) updates from Microsoft this month. However there are a number of important updates which have been revised exterior of the Patch Tuesday calendar together with: CVE-2023-36792, CVE-2023-36793, CVE-2023-36794 and CVE-2023-36796.

All of those reported CVE entries relate to a cluster of Visible Studio distant code execution vulnerabilities. Microsoft is rereleasing KB5029365 to handle the next recognized subject: Prospects who’re utilizing Microsoft Visible Studio 2013 Replace 5 may obtain a “C2471” error after making an attempt to compile a construct that has precompiled headers (PCH) that use the /Gm and /ZI (Edit and Proceed) switches.

These re-releases of those 4 Visible Studio updates (from September) are rated important by Microsoft and can must be added to your “Patch Now” launch schedule.

Adobe Reader (nonetheless right here, however simply not this month)

There have been no updates from Adobe for Reader or Acrobat this month. And no updates to third-party purposes such WinRAR nor deprecations to main system elements. Now that now we have a little bit of time left within the 12 months, we will begin speaking concerning the potential compatibility points in Home windows 23H2.

For Patch Tuesday Debugged, that is a wrap for 2023. It has been a pleasure and a privilege to assist with Patch Tuesday testing and deployment challenges over the previous 12 months. I am unable to wait to see what 2024 will carry us.

Copyright © 2023 IDG Communications, Inc.

UrbanPLR Ad

Source link

Team News Nation Live

Team News Nation Live

Subscribe to Our Newsletter

Keep in touch with our news & offers