July Sees Microsoft Addressing Four Critical Zero-Day Vulnerabilities

To ensure seamless PowerShell updates, a diagnostic test is now mandatory. Execute the command “import-module Microsoft.powershell.diagnostics – verbose” and ascertain the accuracy of the outcomes from your primary directory.

[…Keep reading]

For July, Microsoft’s Patch Tuesday update fixes four zero-day flaws

To ensure seamless PowerShell updates, a diagnostic test is now mandatory. Execute the command “import-module Microsoft.powershell.diagnostics – verbose” and ascertain the accuracy of the outcomes from your primary directory.

Following the Windows core installation technology shift to MSI, it is imperative to confirm the continued effectiveness of User Account Control (UAC).

Microsoft SQL Server

This month witnesses a substantial update for Microsoft SQL Server and the supporting components of OLE on local or workstation systems. The primary emphasis in such a multifaceted endeavor should be on your critical business applications. These applications typically entail varied data connections and rely on intricate object/session requirements. In light of the recent modifications, we refrain from prescribing specific Windows feature testing routines and instead urge a comparative evaluation across untouched and recently patched systems to detect any potential data discrepancies.

Windows

Microsoft introduced further enhancements to the Win32 and GDI subsystems with a suggestion to thoroughly evaluate a significant segment of your application suite. Additionally, we propose comprehensive testing of the subsequent functional areas within the Windows ecosystem:

– Verify the performance of file compression updates by examining scenarios of file and archive extraction.
– Following the codec updates from Microsoft, conduct a system reboot and validate the seamless functioning of audio and camera functionalities.
– With the installation of security updates, it is essential to test the creation of new Windows certificates.
– Networking adjustments necessitate testing of DNS and DHCP functionalities, particularly the DHCP R_DhcpAddSubnetElement API. Additionally, as part of these changes, authentication testing for VPN connections becomes mandatory. Endeavor to incorporate your Network Policy Server (NPS) in the connection setup and deletion procedures.
– The latest update to Remote Desktop Services (RDS) demands the issuance and invalidation of license requests.
– A significant modification to the Network Driver Interface Specification (NDIS) mandates testing of network traffic when handling repeated bursts of large files. Employ Teams during this network “burst” evaluation phase.
– Given the updates to backup and printing operations, it is advisable to validate your volumes and ensure that printing a test page does not lead to system crashes. Consider printing TIFF files for testing purposes.

In line with the ongoing commitment to facilitate the new ARM architecture, Microsoft has rolled out the premier patch for this platform, CVE-2024-37985. This vulnerability, initially associated with Intel processors, has been neutralized via a patch at the Microsoft OS level. The Readiness team has furnished guidance on probable compatibility and testing challenges associated with the ARM architecture.

About Author

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.