Using a thing made by Microsoft, Apple or Adobe? It probably needs a patch today

Windows, Win Server, Office, Edge, IE, Silverlight, Flash, iOS, watchOS...


Mega Patch Tuesday Microsoft is wrapping up the summer with a dump of 14 bulletins for various security vulnerabilities in its products, while Apple and Adobe are following up with fixes of their own.

The September edition of Patch Update Tuesday sees fixes released for critical issues in Windows, Windows Server, Internet Explorer, Edge, Flash Player, iOS, Xcode, and the Apple Watch.

For Microsoft, the September security load consists of the following:

  • MS16-104 An update to address ten vulnerabilities in Internet Explorer, including multiple flaws that, if targeted, allow an attacker to execute remote code execution, escape sandbox protections, or view memory content when the victim visits a specially crafted webpage.
  • MS16-105 A cumulative update for the Edge browser, patching 12 CVE-listed flaws, including seven remote code execution vulnerabilities, via malformed web pages. Also patched are information disclosure bugs that can be exploited via PDF files.
  • MS16-106 Fixes five holes in the Windows Graphics Device Interface that can be exploited by simply opening an image file or viewing a page embedded with attack code.
  • MS16-107 Patches seven security vulnerabilities in Office that allow remote code execution by way of memory corruption and private key theft by malicious Visual Basic macros.
  • MS16-108 Covers three bugs in Exchange Server that allow for user account information disclosure, elevation of privilege, and page spoofing via links embedded in email messages. The bulletin also includes a patch from Oracle to address multiple vulnerabilities in Exchange's Oracle Outside In library.
  • MS16-109 Addresses a remote code execution in Silverlight, including versions for Mac and Silverlight Developer Runtime.
  • MS16-110 An update for Windows to address four networking flaws, including a denial of service and two remote code execution vulnerabilities, and an information disclosure flaw that allows brute-force guessing of user passwords.
  • MS16-111 Fixes five elevation of privilege vulnerabilities in Windows Kernel that allow a user to hijack or steal the login credentials of other users.
  • MS16-112 Patches an elevation of privilege flaw that allows a malicious Wi-Fi hotspot to display web content on the lock screen of the targeted user.
  • MS16-113 Fixes a vulnerability in the Windows Kernel Secure Mode that allows a locally-installed malicious application to view object in memory.
  • MS16-114 A patch for a remote code execution flaw in SMB Server that allows an attacker to take over a targeted server running Windows Server 2008 or crash a system running Server 2012.
  • MS16-115 Patches a pair of bugs in Windows PDF Library that allow a malicious PDF file to access objects in memory.
  • MS16-116 Fixes a remote code execution flaw in Microsoft OLE Automation mechanism and the VBScript Scripting Engine that allows a specially crafted webpage to take over the targeted system. The fix also requires that the Internet Explorer update (MS16-104) be installed in order to be effective.
  • MS16-117 Microsoft's update for Adobe Flash Player on Windows and Windows Server. The fix, listed by Microsoft as critical, addresses 26 of the type of security flaws that have earned Flash its reputation as the Internet's Screen Door.

Other stories you might like

  • New audio server Pipewire coming to next version of Ubuntu
    What does that mean? Better latency and a replacement for PulseAudio

    The next release of Ubuntu, version 22.10 and codenamed Kinetic Kudu, will switch audio servers to the relatively new PipeWire.

    Don't panic. As J M Barrie said: "All of this has happened before, and it will all happen again." Fedora switched to PipeWire in version 34, over a year ago now. Users who aren't pro-level creators or editors of sound and music on Ubuntu may not notice the planned change.

    Currently, most editions of Ubuntu use the PulseAudio server, which it adopted in version 8.04 Hardy Heron, the company's second LTS release. (The Ubuntu Studio edition uses JACK instead.) Fedora 8 also switched to PulseAudio. Before PulseAudio became the standard, many distros used ESD, the Enlightened Sound Daemon, which came out of the Enlightenment project, best known for its desktop.

    Continue reading
  • VMware claims 'bare-metal' performance on virtualized GPUs
    Is... is that why Broadcom wants to buy it?

    The future of high-performance computing will be virtualized, VMware's Uday Kurkure has told The Register.

    Kurkure, the lead engineer for VMware's performance engineering team, has spent the past five years working on ways to virtualize machine-learning workloads running on accelerators. Earlier this month his team reported "near or better than bare-metal performance" for Bidirectional Encoder Representations from Transformers (BERT) and Mask R-CNN — two popular machine-learning workloads — running on virtualized GPUs (vGPU) connected using Nvidia's NVLink interconnect.

    NVLink enables compute and memory resources to be shared across up to four GPUs over a high-bandwidth mesh fabric operating at 6.25GB/s per lane compared to PCIe 4.0's 2.5GB/s. The interconnect enabled Kurkure's team to pool 160GB of GPU memory from the Dell PowerEdge system's four 40GB Nvidia A100 SXM GPUs.

    Continue reading
  • Nvidia promises annual updates across CPU, GPU, and DPU lines
    Arm one year, x86 the next, and always faster than a certain chip shop that still can't ship even one standalone GPU

    Computex Nvidia's push deeper into enterprise computing will see its practice of introducing a new GPU architecture every two years brought to its CPUs and data processing units (DPUs, aka SmartNICs).

    Speaking on the company's pre-recorded keynote released to coincide with the Computex exhibition in Taiwan this week, senior vice president for hardware engineering Brian Kelleher spoke of the company's "reputation for unmatched execution on silicon." That's language that needs to be considered in the context of Intel, an Nvidia rival, again delaying a planned entry to the discrete GPU market.

    "We will extend our execution excellence and give each of our chip architectures a two-year rhythm," Kelleher added.

    Continue reading
  • Amazon puts 'creepy' AI cameras in UK delivery vans
    Big Bezos is watching you

    Amazon is reportedly installing AI-powered cameras in delivery vans to keep tabs on its drivers in the UK.

    The technology was first deployed, with numerous errors that reportedly denied drivers' bonuses after malfunctions, in the US. Last year, the internet giant produced a corporate video detailing how the cameras monitor drivers' driving behavior for safety reasons. The same system is now apparently being rolled out to vehicles in the UK. 

    Multiple camera lenses are placed under the front mirror. One is directed at the person behind the wheel, one is facing the road, and two are located on either side to provide a wider view. The cameras are monitored by software built by Netradyne, a computer-vision startup focused on driver safety. This code uses machine-learning algorithms to figure out what's going on in and around the vehicle.

    Continue reading
  • AWS puts latest homebrew ‘Graviton 3’ Arm CPU in production
    Just one instance type for now, but cheaper than third-gen Xeons or EPYCs

    Amazon Web Services has made its latest homebrew CPU, the Graviton3, available to rent in its Elastic Compute Cloud (EC2) infrastructure-as-a-service offering.

    The cloud colossus launched Graviton3 at its late 2021 re:Invent conference, revealing that the 55-billion-transistor device includes 64 cores, runs at 2.6GHz clock speed, can address DDR5 RAM and 300GB/sec max memory bandwidth, and employs 256-bit Scalable Vector Extensions.

    The chips were offered as a tech preview to select customers. And on Monday, AWS made them available to all comers in a single instance type named C7g.

    Continue reading

Biting the hand that feeds IT © 1998–2022