=================================================================== CERT-Renater Note d'Information No. 2022/VULN265 _____________________________________________________________________ DATE : 11/08/2022 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running .NET 6.0; .NET Core 3.1; Azure Batch; Azure Real Time Operating System GUIX Studio; Azure Site Recovery VMWare to Azure; Azure Sphere; Microsoft 365 Apps for Enterprise for 32-bit Systems; Microsoft 365 Apps for Enterprise for 64-bit Systems; Microsoft Edge (Chromium-based); Microsoft Excel 2013 RT Service Pack 1; Microsoft Excel 2013 Service Pack 1 (32-bit editions); Microsoft Excel 2013 Service Pack 1 (64-bit editions); Microsoft Excel 2016 (32-bit edition); Microsoft Excel 2016 (64-bit edition); Microsoft Exchange Server 2013 Cumulative Update 23; Microsoft Exchange Server 2016 Cumulative Update 22; Microsoft Exchange Server 2016 Cumulative Update 23; Microsoft Exchange Server 2019 Cumulative Update 11; Microsoft Exchange Server 2019 Cumulative Update 12; Microsoft Office 2013 RT Service Pack 1; Microsoft Office 2013 Service Pack 1 (32-bit editions); Microsoft Office 2013 Service Pack 1 (64-bit editions); Microsoft Office 2016 (32-bit edition); Microsoft Office 2016 (64-bit edition); Microsoft Office 2019 for 32-bit editions; Microsoft Office 2019 for 64-bit editions; Microsoft Office LTSC 2021 for 32-bit editions; Microsoft Office LTSC 2021 for 64-bit editions; Microsoft Office Online Server; Microsoft Outlook 2013 RT Service Pack 1; Microsoft Outlook 2013 Service Pack 1 (32-bit editions); Microsoft Outlook 2013 Service Pack 1 (64-bit editions); Microsoft Outlook 2016 (32-bit edition); Microsoft Outlook 2016 (64-bit edition); Microsoft Visual Studio 2012 Update 5; Microsoft Visual Studio 2013 Update 5; Microsoft Visual Studio 2015 Update 3; Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8); Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10); Microsoft Visual Studio 2019 version 16.9 (includes 16.0 - 16.8); Microsoft Visual Studio 2022 version 17.0; Microsoft Visual Studio 2022 version 17.2; Open Management Infrastructure; System Center Operations Manager (SCOM) 2016; System Center Operations Manager (SCOM) 2019; System Center Operations Manager (SCOM) 2022; Windows 10 for 32-bit Systems; Windows 10 for x64-based Systems; Windows 10 Version 1607 for 32-bit Systems; Windows 10 Version 1607 for x64-based Systems; Windows 10 Version 1809 for 32-bit Systems; Windows 10 Version 1809 for ARM64-based Systems; Windows 10 Version 1809 for x64-based Systems; Windows 10 Version 20H2 for 32-bit Systems; Windows 10 Version 20H2 for ARM64-based Systems; Windows 10 Version 20H2 for x64-based Systems; Windows 10 Version 21H1 for 32-bit Systems; Windows 10 Version 21H1 for ARM64-based Systems; Windows 10 Version 21H1 for x64-based Systems; Windows 10 Version 21H2 for 32-bit Systems; Windows 10 Version 21H2 for ARM64-based Systems; Windows 10 Version 21H2 for x64-based Systems; Windows 11 for ARM64-based Systems; Windows 11 for x64-based Systems; Windows 7 for 32-bit Systems Service Pack 1; Windows 7 for x64-based Systems Service Pack 1; Windows 8.1 for 32-bit systems; Windows 8.1 for x64-based systems; Windows RT 8.1; Windows Server 2008 for 32-bit Systems Service Pack 2; Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation); Windows Server 2008 for x64-based Systems Service Pack 2; Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation); Windows Server 2008 R2 for x64-based Systems Service Pack 1; Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation); Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); Windows Server 2016; Windows Server 2016 (Server Core installation); Windows Server 2019; Windows Server 2019 (Server Core installation); Windows Server 2022; Windows Server 2022 (Server Core installation); Windows Server, version 20H2 (Server Core Installation) ====================================================================https://msrc.microsoft.com/update-guide/ _____________________________________________________________________ ********************************************************************* Microsoft Security Update Summary for August 9, 2022 Issued: August 9, 2022 ******************************************************************** This summary lists security updates released for August 9, 2022. Complete information for the August 2022 security update release Can be found at . IMPORTANT ANNOUNCEMENT: It's time to create your profile in the Security Update Guide (SUG) and sign up to receive Microsoft Technical Security Notifications. See Security Update Guide Notification System News: Create your profile now (https://aka.ms/SUGNotificationProfile2) for more information. Please note the following information regarding the security updates: * Windows 10 updates are cumulative. The monthly security release includes all security fixes for vulnerabilities that affect Windows 10, in addition to non-security updates. The updates are available via the Microsoft Update Catalog: https://catalog.update.microsoft.com/v7/site/Home.aspx. * For information on lifecycle and support dates for Windows 10 operating systems, please see the Windows Lifecycle Facts Sheet: https://support.microsoft.com/en-us/help/13853/windows- lifecycle-fact-sheet). * A list of the latest servicing stack updates for each operating system can be found in ADV990001: https://msrc.microsoft.com/update- guide/vulnerability/ADV990001. This list will be updated whenever a new servicing stack update is released. It is important to install the latest servicing stack update. * In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features. * Customers running Windows 7, Windows Server 2008 R2, or Windows Server 2008 need to purchase the Extended Security Update to continue receiving security updates. See https://support.microsoft.com/en-us/help/4522133/procedure-to- continue-receiving-security-updates for more information. * There is a change coming with regards to Servicing Stack Updates. Please see Simplifying SSUs for more information. Critical Security Updates ==========================Windows 10 for 32-bit Systems Windows 10 for x64-based Systems Windows 10 Version 1607 for 32-bit Systems Windows 10 Version 1607 for x64-based Systems Windows 10 Version 1809 for 32-bit Systems Windows 10 Version 1809 for ARM64-based Systems Windows 10 Version 1809 for x64-based Systems Windows 10 Version 20H2 for 32-bit Systems Windows 10 Version 20H2 for ARM64-based Systems Windows 10 Version 20H2 for x64-based Systems Windows 10 Version 21H1 for 32-bit Systems Windows 10 Version 21H1 for ARM64-based Systems Windows 10 Version 21H1 for x64-based Systems Windows 10 Version 21H2 for 32-bit Systems Windows 10 Version 21H2 for ARM64-based Systems Windows 10 Version 21H2 for x64-based Systems Windows 11 for ARM64-based Systems Windows 11 for x64-based Systems Windows 8.1 for 32-bit systems Windows 8.1 for x64-based systems Windows RT 8.1 Windows Server 2012 Windows Server 2012 (Server Core installation) Windows Server 2012 R2 Windows Server 2012 R2 (Server Core installation) Windows Server 2016 Windows Server 2016 (Server Core installation) Windows Server 2019 Windows Server 2019 (Server Core installation) Windows Server 2022 Windows Server 2022 (Server Core installation) Windows Server, version 20H2 (Server Core Installation) Microsoft Exchange Server 2013 Cumulative Update 23 Microsoft Exchange Server 2016 Cumulative Update 22 Microsoft Exchange Server 2016 Cumulative Update 23 Microsoft Exchange Server 2019 Cumulative Update 11 Microsoft Exchange Server 2019 Cumulative Update 12 Azure Batch Important Security Updates ==========================Microsoft 365 Apps for Enterprise for 32-bit Systems Microsoft 365 Apps for Enterprise for 64-bit Systems Microsoft Excel 2013 RT Service Pack 1 Microsoft Excel 2013 Service Pack 1 (32-bit editions) Microsoft Excel 2013 Service Pack 1 (64-bit editions) Microsoft Excel 2016 (32-bit edition) Microsoft Excel 2016 (64-bit edition) Microsoft Office 2013 RT Service Pack 1 Microsoft Office 2013 Service Pack 1 (32-bit editions) Microsoft Office 2013 Service Pack 1 (64-bit editions) Microsoft Office 2016 (32-bit edition) Microsoft Office 2016 (64-bit edition) Microsoft Office 2019 for 32-bit editions Microsoft Office 2019 for 64-bit editions Microsoft Office LTSC 2021 for 32-bit editions Microsoft Office LTSC 2021 for 64-bit editions Microsoft Office Online Server Microsoft Outlook 2013 RT Service Pack 1 Microsoft Outlook 2013 Service Pack 1 (32-bit editions) Microsoft Outlook 2013 Service Pack 1 (64-bit editions) Microsoft Outlook 2016 (32-bit edition) Microsoft Outlook 2016 (64-bit edition) .NET 6.0 .NET Core 3.1 Microsoft Visual Studio 2012 Update 5 Microsoft Visual Studio 2013 Update 5 Microsoft Visual Studio 2015 Update 3 Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8) Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10) Microsoft Visual Studio 2019 version 16.9 (includes 16.0 - 16.8) Microsoft Visual Studio 2022 version 17.0 Microsoft Visual Studio 2022 version 17.2 System Center Operations Manager (SCOM) 2016 System Center Operations Manager (SCOM) 2019 System Center Operations Manager (SCOM) 2022 Open Management Infrastructure Azure Real Time Operating System GUIX Studio Azure Site Recovery VMWare to Azure Azure Sphere Other Information Recognize and avoid fraudulent email to Microsoft customers: ============================================================If you receive an email message that claims to be distributing a Microsoft security update, it is a hoax that may contain malware or pointers to malicious websites. Microsoft does not distribute security updates via email. The Microsoft Security Response Center (MSRC) uses PGP to digitally sign all security notifications. However, PGP is not required for reading security notifications, reading security information, or installing security updates. You can obtain the MSRC public PGP key at . ******************************************************************** THE INFORMATION PROVIDED IN THIS MICROSOFT COMMUNICATION IS PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING LIMITATION MAY NOT APPLY. Microsoft respects your privacy. Please read our online Privacy Statement at . If you would prefer not to receive future technical security notification alerts by email from Microsoft and its family of companies please visit the following website to unsubscribe: . These settings will not affect any newsletters you've requested or any mandatory service communications that are considered part of certain Microsoft services. For legal Information, see: . This newsletter was sent by: Microsoft Corporation 1 Microsoft Way Redmond, Washington, USA 98052 ******************************************************************** Microsoft Security Update Summary for August 9, 2022 Issued: August 9, 2022 ******************************************************************** ========================================================+ CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + ======================================================= --------------cUa0XDjwIK0pd0Hxf8FqyG97--