• December 2021 Patch Tuesday arrives – say goodbye to 2004

    It’s that day of the month again when we turn and look (northward in my case, your location may vary) to Redmond and see what Holiday helpings they are serving this time. For those of you in businesses, you are probably not wanting to see any more patch notifications right now after dealing with all of the Log4shell patching you’ve been having to do lately. What got found in an online gaming platform is now causing patching headaches for many businesses because they all used this code in their logging software.

    https://twitter.com/GossiTheDog/status/1470787395805192199

    Even if you are a gamer, YOU aren’t the patcher in the Log4shell patching situation, it’s the cloud and application vendors. This code is not native to Windows operating systems. You may see a lot of headlines about businesses impacted by coin-mining attacks or ransomware. Reportedly Kronos a payroll company was hit with a Log4shell attack.

    For the windows updates this does have the printing fixes now rolled up in them and here’s hoping no new printer side effects will be introduced.

    https://msrc.microsoft.com/update-guide/releaseNote/2021-Dec

    6 Zero days
    21 Elevation of Privilege Vulnerabilities
    26 Remote Code Execution Vulnerabilities
    10 Information Disclosure Vulnerabilities
    3 Denial of Service Vulnerabilities
    7 Spoofing Vulnerabilities

    And a partridge in a pear tree

    The updates have just started rolling out, again, as per normal rules of Askwoody patching engagement, you the home user want to hold back and wait to see what side effects occur. We’ll keep an eye out for you.