Category: Microsoft|Jun 15, 2024 | Author: Admin

Microsoft delivers a light Patch Tuesday for June

Share on

This month's Patch Tuesday release included 49 updates, but no major zero-day flaws.

Microsoft delivers a light Patch Tuesday for June

Microsoft this week released 49 updates (including two recent additions) on Patch Tuesday with no reported zero-day flaws, public disclosures, or newly released working exploits for the Microsoft ecosystem. This came as welcome news and is paired with low-risk changes to Microsoft Office. The company’s development platforms saw minor updates to Visual Studio, and both SQL Server and Microsoft Exchange were patch-free for the month.

 

Known issues 
Each month, Microsoft publishes a list of known issues that are part of the latest update cycle, including the following reported minor issues:

 

After you install KB5034203 (dated 01/23/2024) or later updates, some Windows devices that use the DHCP Option 235 to discover Microsoft Connected Cache (MCC) nodes in their network might be unable to use those nodes. Microsoft is still working on this one. In the meantime, there is a workaround that involves setting the Cache Hostname to 1. 

 

We recognize and respect Microsoft’s recent efforts with artificial intelligence (note, I did not say “AI” as that is an Apple thing now) but it would be nice if Microsoft resolved the profile picture (that you can’t change) known issue soon. 

 

Major revisions 
Microsoft published the following major revisions to past security and feature updates including:


CVE-2024-30080: (see below for mitigations). This patch was updated late in the June release cycle. As this was an information update, no further action is required, unless you want to action the Microsoft recommended mitigations.
Mitigations and workarounds
Microsoft published the following vulnerability-related mitigations:

 

CVE-2024-30070: DHCP Server Service Denial of Service Vulnerability. Microsoft (helpfully) notes that if you’re not using DHCP, you are not affected by this potential vector for DDOS attacks. 
CVE-2024-30080: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability. Message Queuing security issues are tough to find, mitigate and test, so this might need some careful attention from your internal developers. At the very least, ensure that you have changed your ports from the MSMQ listening default (1801) to help reduce your attack surface. Microsoft also recommends you check to see whether the MSMQ HTTP-Support feature is enabled.
The team at Readiness analyzed the latest Patch Tuesday updates to provide detailed, actionable testing guidance based on assessing a large application portfolio and a detailed analysis of the Microsoft patches and their potential impact.

 

For this cycle, we have grouped the critical updates and required testing efforts into different functional areas including:

 

 

Microsoft Office

  • Microsoft SharePoint will require basic document opening and multi-user access tests this month.

 

Microsoft .NET and Developer Tools

  • There are no updates to Microsoft .NET requiring application portfolio testing this month.
    Windows

 

The following core Microsoft features have been updated:

 

  • Changes to Secure Boot will require testing of all third-party drivers.
  • Code integrity policies need to be verified for Windows Lockdown (WLDP), Windows Defender Application Guard (WDAG), and the Windows Driver Policy for Intune deployments. We recommend you test your Windows desktop sandbox and
  • ensure that it boots correctly.
  • Changes to Windows networking will require testing at least two DHCP servers.
  • Remote desktop-related updates will require VPN connection tests. Try some administrative commands from the Microsoft Management Console (MMC) such as adding, connecting, and disconnecting VPN connections.

 


This month’s update also affects several core systems such as Kernel32 and Win32K.SYS sub-systems. Unfortunately, these changes affect how applications behave at a fundamental level, which makes testing not just hard, but broad and expansive across your application portfolio. The Readiness team suggests that the following general application tests be performed against all of your core line-of-business applications.

 

  • Test as many windows and pop-ups as possible.
  • Check window title bars for errors, or poorly formatted text.
  • Check for unusual items in the Windows taskbar.
  • Thoroughly test File Explorer (sorry about that).
  • Test multiple applications, with multiple windows.

 


Automated testing will help with these scenarios (especially a testing platform that offers a “delta” or comparison between builds). However, for your line-of-business apps, getting the application owner (doing UAT) to test and approve the results is essential.

 

Windows lifecycle update
This section contains important changes to servicing (and most security updates) to the Windows desktop and server platform

 

  • Windows 10 Enterprise and Education, Version 21H2 will no longer be serviced as of June 11, 2024


For those planning ahead, Oct. 8, 2024, is a big day as Microsoft will no longer offer general servicing for the following desktop platforms:

 

  • Windows 11 Enterprise and Education, Version 21H2
  • Windows 11 Home and Pro, Version 22H2
  • Windows 11 IoT Enterprise, Version 21H2


Each month, we break down the update cycle into product families (as defined by Microsoft) with the following basic groupings:

 

  • Browsers (Microsoft IE and Edge)
  • Microsoft Windows (both desktop and server) 
  • Microsoft Office
  • Microsoft Exchange Server 
  • Microsoft Development platforms (ASP.NET Core, .NET Core, and Chakra Core)
  • Adobe (if you get this far)


Browsers
Microsoft has released seven minor updates to the Chromium-based browser (Edge), while the Chromium project has added six additional updates this week. These updates should have minor to negligible impact on applications that integrate and operate on Chromium. Add these updates to your standard patch release schedule.

Windows
This month, Microsoft released one critical update (CVE-2024-30080) and 32 patches rated as important for Windows, covering the following key components:

 

  • Windows Win32 Kernel Subsystem, GRFX, and drivers
  • Networking (Wii-fi) and DHCP
  • Storage and Error Reporting
  • Crypto and BitLocker
  • The critical-rated patch relates to the core, but not often used, Message Queuing service (MSMQ) that could affect internal applications. Unusually, this patch has already been updated since the main release on Tuesday. That said, the Readiness team believes all these Windows patches can be added to your standard release schedule.

 

Microsoft Office 
There were no critical updates for Office this month, and only five patches were rated as important. All five have low potential for exploitability (no worms, add-in vulnerabilities, or Word macro issues) and should be added to your regular Microsoft Office update schedule.

Microsoft Exchange Server 
No updates for Microsoft Exchange Server or SQL Server this month, which, of course, is a good thing. 

 

Microsoft development platforms 
Microsoft released just three updates to Microsoft Visual Studio. These patches affect versions of the Microsoft developer platform from 2017 to 2022. All of the proposed changes are low-risk and application specific. Add these updates to your standard developer release schedule.

Sponsored Ads:

Comments:


Chrome_flare-21-05-25.png

Data-stealing Chrome extensions impersonate Fortinet, YouTube, VPNs

Category: Google|May 21, 2025 | Author: Admin
ChatGPT_headpic-20-05-25.png

OpenAI plans to combine multiple models into GPT-5

Category: IT|May 20, 2025 | Author: Admin
Cell-towers-19-05-25.png

O2 UK patches bug leaking mobile user location from call metadata

Category: IT|May 19, 2025 | Author: Admin
Windows_BitLocker-18-05-25.png

Microsoft confirms May Windows 10 updates trigger BitLocker recovery

Category: Microsoft|May 18, 2025 | Author: Admin
karljohan-17-05-25.jpg

Gratulerer med 17. mai!

Category: Norge|May 17, 2025 | Author: Admin
ChatGPT-16-05-25.png

ChatGPT rolls out Codex, an AI tool for software programming

Category: IT|May 16, 2025 | Author: Admin
Google-Chrome-headpic-15-05-25.png

Google Chrome to block admin-level browser launches for better security

Category: Google|May 15, 2025 | Author: Admin
Linux-14-05-25.png

Microsoft fixes Linux boot issues on dual-boot Windows systems

Category: Microsoft|May 14, 2025 | Author: Admin
Windows_11-13-05-25.png

Windows 11 upgrade block lifted after Safe Exam Browser fix

Category: Microsoft|May 13, 2025 | Author: Admin
bluetooth-12-05-25.png

Bluetooth 6.1 enhances privacy with randomized RPA timing

Category: IT|May 12, 2025 | Author: Admin
ChatGPT-22-05-25.png

ChatGPT is finally adding Download as PDF for Deep Research

Category: IT|May 11, 2025 | Author: Admin
Microsoft-Teams-10-05-25.png

Microsoft Teams will soon block screen capture during meetings

Category: Microsoft|May 10, 2025 | Author: Admin
cryptocurrency-header-09-05-25.png

Germany takes down eXch cryptocurrency exchange, seizes servers

Category: IT|May 9, 2025 | Author: Admin
Discord-08-05-25.png

Malicious PyPi package hides RAT malware, targets Discord devs since 2022

Category: IT|May 8, 2025 | Author: Admin
WordPress-headpic-07-05-25.png

Hackers exploit OttoKit WordPress plugin flaw to add admin accounts

Category: IT|May 7, 2025 | Author: Admin
more