• Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
Blog - Creative Collaboration
No Result
View All Result
Home Internet

Unscheduled fixes for critical Windows flaws delivered through rare channel

July 1, 2020
Share on FacebookShare on Twitter

Microsoft has published unscheduled fixes for two critical vulnerabilities that make it possible for attackers to execute malicious code on computers running any version of Windows 10.

Unlike the vast majority of Windows patches, the ones released on Tuesday were delivered through the Microsoft Store. The normal channel for operating System security fixes is Windows Update. Advisories here and here said users need not take any action to automatically receive and install the fixes.

“Affected customers will be automatically updated by Microsoft Store. Customers do not need to take any action to receive the update,” both advisories said. “Alternatively, customers who want to receive the update immediately can check for updates with the Microsoft Store App; more information on this process can be found here.”

When I checked both the Microsoft Store and the Windows Update on my Windows 10 laptop, however, I saw no confirmation that the patch had been installed. Normally, Windows 10 users can use the Windows Update tab within the Update and Security settings section to ensure patches have been installed. The link provided in the advisories offered no clarity. Microsoft representatives didn’t immediately respond to questions for clarification.

Both vulnerabilities reside in Windows code libraries that manage codecs used to render images or other multimedia content. Attackers can exploit the flaws to execute code of their choice or to obtain information stored on vulnerable systems. Exploits can be delivered in specially designed image files that corrupt computer memory. Presumably, the images could be delivered on compromised websites a target visits or when targets open a malicious file sent by email. Tuesday’s advisories didn’t say if exploits worked only when targets opened the malformed images in specific apps or any app.

Microsoft credited Abdul-Aziz Hariri of Trend Micro’s Zero Day Initiative with discovering and privately reporting the bugs. Both advisories indicate that there’s no evidence of the flaw being actively exploited in the wild. With no clear way to verify the patches have been installed, Windows 10 users for now will have to take Microsoft’s word that they’re automatically installed. This post will be updated if Microsoft responds to our questions.

Next Post

Here’s what it got wrong – TechCrunch

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

No Result
View All Result

Recent Posts

  • Samsung might already be done selling the Galaxy Z TriFold
  • Best Magic The Gathering deal: Duskmourn Play Booster Box under $130 at Walmart
  • Meta signs $27B deal with Nebius
  • UK government unveils gigabit broadband upgrade tracker
  • Oscars 2026: Watch Jessie Buckley’s moving speech

Recent Comments

    No Result
    View All Result

    Categories

    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi
    • Home
    • Shop
    • Privacy Policy
    • Terms and Conditions

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    No Result
    View All Result
    • Home
    • Blog
    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    Get more stuff like this
    in your inbox

    Subscribe to our mailing list and get interesting stuff and updates to your email inbox.

    Thank you for subscribing.

    Something went wrong.

    We respect your privacy and take protecting it seriously