News, tips, advice, support for Windows, Office, PCs & more. Tech help. No bull. We're community supported by donations from our Plus Members, and proud of it
Home icon Home icon Home icon Email icon RSS icon
  • January security patches are out

    Posted on January 9th, 2018 at 12:22 woody Comment on the AskWoody Lounge

    The Release Notes are up. A total of 93 separate patches.

    SANS Internet Storm Center posted its usual list. 

    No known exploits.

    Weird. The Jan. 3 patches are listed in the Update Summary Guide as Jan. 9.

    Holy Guacamole, Bitman. Martin Brinkmann just posted his overview at ghacks.net and it goes on for pages and pages and pages.

    There’s some confusion about the Equation Editor vulnerability. You may recall that the original hole, CVE-2017-11882, was patched in November. This new patch, for CVE-2018-0802, takes the nuclear option — it removes Equation Editor from Word. @yuhong2 advises on Twitter that the Eqn Editor EXE turns into 0 bytes, so it’s even dead with WordPad.

    UPDATE: It looks like the Equation Editor patch is the only patch in this month’s crop that has known exploits.