Patching in Review – Week 22 of 2019
While there has yet to be an active exploit to BlueKeep, Microsoft posted a new TechNet article yesterday urging the world to update their systems to prevent this worm from reaching the level that WannaCry did with this important point:
"It only takes one vulnerable computer connected to the internet to provide a potential gateway into these corporate networks, where advanced malware could spread, infecting computers across the enterprise."
We will continue to update our BlueKeep blog as the information on this vulnerability continues to develop, so keep that link bookmarked!
Windows 10 1903 has been publicly available for around 10 days now, and compatibility issues are just starting to roll in. Although these issues are not as severe as the infamous “file deletion” issue found from the 1809 rollout, the installation may fail on certain hardware configurations. Consequently, Microsoft has updated its rollout logic as it finds issues. Of the issues currently reported, here are a few to stay aware of as you roll this out to test groups:
- Error updating machines with external USB device or Memory Card attached
- Loss of Wi-Fi connectivity on outdated Qualcomm drivers
- Failure to install on systems with out-of-date Intel Display Audio Drivers
- Deployment failure on systems with out-of-date AMD RAID drivers
Security Updates
While Patch Tuesday was more than eventful, security releases have been infrequent since, with only a single release from Apple. iTunes 12.9.5.7 and iCloud 7.12.0.14 were both released this week covering a total of 26 CVEs. While Apple does not disclose the severity of these CVEs, make sure to include these in your next patching cycle as this uncommon software within an enterprise can still be used for an attack vector.
Third-Party Updates
During this week our other supported vendors have been busy releasing additional stability fixes for their software. Review the list below and take note of any software within your environment:
Software Title |
Ivanti ID |
Ivanti KB |
Apple Mobile Device Support 12.2.1.12 |
AMDS-025 |
QAMDS122112 |
Beyond Compare 4.2.10.23938 |
BEYOND-009 |
QBC421023938 |
Microsoft Power BI Desktop 2.69.5467.2151 |
PBID-057 |
QBI26954672151 |
Camtasia 2019.0.2 |
CAMTA-016 |
QCAMTASIA1902 |
Nitro Pro 12.14.0.558 |
NITRO-024 |
QNITRO12140558 |
Nitro Pro Enterprise 12.14.0.558 |
NITROE-005 |
QNITROE12140558 |
Node.JS 10.16.0 (LTS Upper) |
NOJSLU-008 |
QNODEJSLU10160 |
Skype 8.46.0.60 |
SKYPE-159 |
QSKY846060 |
WinSCP 5.15.2 |
WINSCP-028 |
QWINSCP5152 |