Stories
Slash Boxes
Comments

SoylentNews is people

posted by Fnord666 on Thursday July 02 2020, @09:57AM   Printer-friendly
from the hole-plugging dept.

Unscheduled fixes released for critical flaw in optional Windows codec

Microsoft has published unscheduled fixes for two critical vulnerabilities that make it possible for attackers to execute malicious code on computers running any version of Windows 10.

Unlike the vast majority of Windows patches, the ones released on Tuesday were delivered through the Microsoft Store. The normal channel for operating System security fixes is Windows Update. Advisories here and here said users need not take any action to automatically receive and install the fixes.

Also at:
Microsoft issues critical fixes for booby-trapped images – update now!


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
(1)
  • (Score: 1, Informative) by Anonymous Coward on Thursday July 02 2020, @10:06AM (4 children)

    by Anonymous Coward on Thursday July 02 2020, @10:06AM (#1015331)

    I am shocked, shocked, I tell you, to discover that there are vulnerabilities in the Micro$oft 0perating Systeme! Why were we not warned?

    • (Score: 2) by driverless on Thursday July 02 2020, @11:30AM (2 children)

      by driverless (4770) on Thursday July 02 2020, @11:30AM (#1015342)

      Microsoft Store ... Microsoft Store ... Microsoft Store ... Microsoft Store

      So in other words anyone who's disabled that shit doesn't need to use that shit to fix the holes in that shit. QED.

      • (Score: 3, Informative) by Freeman on Thursday July 02 2020, @02:22PM (1 child)

        by Freeman (732) on Thursday July 02 2020, @02:22PM (#1015398) Journal

        No, they released the update via Microsoft Store. As far as I understand it, the exploit isn't limited to Microsoft Store apps.

        --
        Joshua 1:9 "Be strong and of a good courage; be not afraid, neither be thou dismayed: for the Lord thy God is with thee"
        • (Score: 5, Interesting) by driverless on Thursday July 02 2020, @02:31PM

          by driverless (4770) on Thursday July 02 2020, @02:31PM (#1015402)

          Could be, but the article makes it out to be a Store circular problem:

          They posited that that the update involved HEVC codecs, which are used in a Windows extension available from the Microsoft Store.

          So you need a Store update to fix a Store problem caused by the Store.

          “That library is responsible for parsing HEIC images with HEVC codec. That library (extension) is available through the Windows Store. And since it's a media codec downloaded from the Windows Store, I assume MS updated it through the Windows Store and not the Windows Update.”

    • (Score: 2) by Freeman on Thursday July 02 2020, @02:19PM

      by Freeman (732) on Thursday July 02 2020, @02:19PM (#1015397) Journal

      Bill Gates showed the kinds of features we can expect from Windows over 20 years ago: https://www.youtube.com/watch?v=IW7Rqwwth84 [youtube.com]

      --
      Joshua 1:9 "Be strong and of a good courage; be not afraid, neither be thou dismayed: for the Lord thy God is with thee"
  • (Score: 0, Touché) by Anonymous Coward on Thursday July 02 2020, @11:35AM (3 children)

    by Anonymous Coward on Thursday July 02 2020, @11:35AM (#1015344)

    Thanks Microsoft, I have no interest in appy apps but I do like security updates. What idiotic diversity hire made the decision to put security updates where they don't belong?

    • (Score: 1, Funny) by Anonymous Coward on Thursday July 02 2020, @12:04PM

      by Anonymous Coward on Thursday July 02 2020, @12:04PM (#1015347)

      Security updates for Windows? Bwahahahaha

    • (Score: 2) by PiMuNu on Thursday July 02 2020, @12:56PM

      by PiMuNu (3823) on Thursday July 02 2020, @12:56PM (#1015370)

      Great if Microsoft is hiring diversity into its senior management.

    • (Score: 0) by Anonymous Coward on Thursday July 02 2020, @05:27PM

      by Anonymous Coward on Thursday July 02 2020, @05:27PM (#1015454)

      I think it was the neo-nazi republican hired to infiltrate and destabilize the liberal west coast tech companies. So go thank uncle.cleetus and grandpa joe for screwing up your incest porn fapfest.

  • (Score: 4, Insightful) by inertnet on Thursday July 02 2020, @12:45PM (1 child)

    by inertnet (4071) on Thursday July 02 2020, @12:45PM (#1015365) Journal

    What Microsoft likes to do is reboot systems into a non responsive state, where a blue screen shows up with a lot of questions, BEFORE startup programs are started. I only run a Windows 10 VM occasionally for testing, but I do get calls from people complaining that their system isn't working. Especially during the Corona crisis, while people are working remotely. The first utterly stupid thing is to reboot someone's computer without asking, but the next even more stupid thing is to reboot it in a non functioning state. With stupid, futile questions on its screen.

    • (Score: 2) by Freeman on Thursday July 02 2020, @02:29PM

      by Freeman (732) on Thursday July 02 2020, @02:29PM (#1015401) Journal

      I already posted the Windows 98 presentation blue screen video above, so won't repeat it here, but it would have been a great place for it.

      My favorites are the "Just a moment ..." with infinite spinning circle of doom and the "It's take a bit longer than usual, but it should be ready soon" screens, with infinite spinning circle of doom. I mean, who's idea was that? Hey, let's give uninformative, Super Obvious statements for the user, that tell them nothing, but dude wait. Without any indication that it's actually doing something or any progress is being made. 'cause that infinite spinning circle of doom, doesn't mean a whole lot.

      --
      Joshua 1:9 "Be strong and of a good courage; be not afraid, neither be thou dismayed: for the Lord thy God is with thee"
  • (Score: 2, Insightful) by Anonymous Coward on Thursday July 02 2020, @02:03PM (2 children)

    by Anonymous Coward on Thursday July 02 2020, @02:03PM (#1015390)

    I've completely disabled the Windows Store on my computer by a hostile takeover of the permissions of the folder it installs the MS Store Apps to and disallowed anything other than myself to write there and I removed the mandatory crapware that's is installed and set up on every new user account from the store.

    ...and now MS is releasing PATCHES through the store???

    The MS Store is absolutely, bar-none the WORST implementation of a digital store I have EVER seen. It's end-user hostile, and it is being used as the channel to feed ads on products I specifically pay for (Yea, I payed for Win 10 Pro). The only way to "manage" it is to completely break it so as to render it 100% useless.

    Release patches in the proper channels MS - because we will NOT install updates from the MS Store.

    • (Score: -1, Troll) by Anonymous Coward on Thursday July 02 2020, @05:55PM

      by Anonymous Coward on Thursday July 02 2020, @05:55PM (#1015467)

      Just be glad they're not sending any of their H1B Indians to shit on your front lawn.

    • (Score: 3, Informative) by Cliron on Thursday July 02 2020, @06:26PM

      by Cliron (11400) on Thursday July 02 2020, @06:26PM (#1015475)

      The reason this was released in the store is to patch the codex from the store.
      If you did not install it from the store, you do not need the patch.

      Similar to, if you did not install FoxIT reader, then you do not need the security update for FoxIT reader.

  • (Score: 0) by Anonymous Coward on Thursday July 02 2020, @07:57PM

    by Anonymous Coward on Thursday July 02 2020, @07:57PM (#1015508)

    i guess the best way to run winblows is disconnected from the net.
    the best way to update winblows is like robbing a bank: a quick in and out (of the net) ...

(1)