August’s Patch Tuesday is a monster: 751 fixes, with an exploited Windows flaw

In the latest updates, users can seamlessly connect to SMB shares, benefiting from features such as RDMA, leases, and Continuous Availability. This allows for the efficient transfer of large data sets in both directions, with the ability to interrupt and reconnect sessions as needed. Additionally, users can take advantage of NTFS extended attributes, UDF mounts, and the cloud-file hydrate and dehydrate functionalities.

For those utilizing Hyper-V, the ability to create, checkpoint, and export Generation 2 virtual machines is now enhanced. Users can enable virtual TPM and BitLocker for added security, as well as connect USB storage and MIDI devices, broadening the scope of device compatibility.

Installation and management of MSI packages have also seen improvements. Users can install, repair, and uninstall packages with ease, while still receiving prompts for User Account Control (UAC) elevation, ensuring a secure operating environment.

Telephony, Networking, and Core Services

The latest updates reveal that TAPI remains the most active component, with 11 entries primarily focused on parity fixes. Other areas addressed include TCP/IP, HTTP.sys, Windows Firewall, Bluetooth, wired 802.1X, and message queuing, showcasing a broad yet shallow approach to enhancements.

  • Users can now exercise TAPI line status and dialing locations against shared lines, while also verifying HTTP.sys functionality under IIS across HTTP/1.1, HTTP/2, and HTTP/3 protocols.
  • Confirmation of TCP/IP IPsec tunnels on both IPv4 and IPv6 is now possible, alongside toggling Windows Firewall rules during restarts. The pairing of Bluetooth headsets, authentication of wired 802.1X, and validation of MSMQ send and receive capabilities have also been streamlined.

Office and SharePoint

This August, the patch cycle has significant implications for click-to-run (C2R), Microsoft 365 Apps, and MSI deployments of Microsoft Office. Key updates include:

  • For MSI Office 2016, users should apply client updates such as Access (KB5002813), the ACE database engine (KB5002832), and various components for Outlook (KB5002755), Word (KB5002901), and VBA (KB5002900). Following these updates, users are encouraged to exercise macros, external data, embedded objects, and line-of-business add-ins.
  • SharePoint Server updates for 2016, 2019, and Subscription Edition require careful attention. After patching, users should check for browser-based editing functionality, keeping in mind that server updates cannot be uninstalled and necessitate a reboot.

Microsoft Exchange Server

This month, on-premises Exchange Server receives a crucial security update addressing seven CVEs across Exchange Server 2016, 2019, and Subscription Edition. This includes one critical elevation of privilege vulnerability and six important issues, which cover further elevation of privilege, remote code execution, denial of service, spoofing, and a security feature bypass. These updates are essential for maintaining a secure and efficient Exchange environment.

Winsage
August’s Patch Tuesday is a monster: 751 fixes, with an exploited Windows flaw