{"id":220325,"date":"2019-07-09T23:49:01","date_gmt":"2019-07-09T21:49:01","guid":{"rendered":"https:\/\/www.borncity.com\/blog\/?p=220325"},"modified":"2022-08-22T10:17:15","modified_gmt":"2022-08-22T08:17:15","slug":"microsoft-security-update-summary-9-juli-2019","status":"publish","type":"post","link":"https:\/\/borncity.com\/blog\/2019\/07\/09\/microsoft-security-update-summary-9-juli-2019\/","title":{"rendered":"Microsoft Security Update Summary (9. Juli 2019)"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline; border-width: 0px;\" title=\"Update\" src=\"https:\/\/borncity.com\/blog\/wp-content\/uploads\/2015\/02\/Update.jpg\" alt=\"Windows Update\" width=\"54\" height=\"54\" align=\"left\" border=\"0\" \/>[<a href=\"https:\/\/borncity.com\/win\/2019\/07\/09\/microsoft-security-update-summary-july-9-2019\/\" target=\"_blank\" rel=\"noopener noreferrer\">English<\/a>]Zum 9. Juli 2019 hat Microsoft zahlreiche Sicherheitsupdates f\u00fcr Windows-Clients und \u2013Server, f\u00fcr Office etc. freigegeben. Hier ein kompakter \u00dcberblick.<\/p>\n<p><!--more--><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg01.met.vgwort.de\/na\/73b0569e991d43f787e00baba57378d7\" alt=\"\" width=\"1\" height=\"1\" \/>Eine Liste der Updates findet sich <a href=\"https:\/\/web.archive.org\/web\/20201101051813\/https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\" target=\"_blank\" rel=\"noopener noreferrer\">auf dieser Microsoft-Seite<\/a>. Details zu den Update-Paketen f\u00fcr Windows, Office etc. gibt es in separaten Blog-Beitr\u00e4gen.<\/p>\n<h2>Servicing Stack Updates<\/h2>\n<p>Microsoft ver\u00f6ffentlicht inzwischen eine \u00dcbersicht \u00fcber alle aktuellen Servicing Stack Updates (SSUs). Die Liste der SSUs findet sich unter <a href=\"https:\/\/web.archive.org\/web\/20201101085445\/https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/ADV990001\" target=\"_blank\" rel=\"noopener noreferrer\">ADV990001<\/a>.<\/p>\n<h2>Anmerkungen zu Updates<\/h2>\n<p>Alle Windows 10 Updates sind kumulativ. Das monatliche Update zum Patchday enth\u00e4lt alle Sicherheitsfixes f\u00fcr Windows 10. Zudem sind alle nicht sicherheitsrelevanten Fixes bis zum Patchday enthalten.<\/p>\n<p>Ab M\u00e4rz 2017 ist f\u00fcr Windows 10 Version 1607 und neuer ein Delta-Paket im Microsoft Update Katalog verf\u00fcgbar. Dieses Delta-Paket enth\u00e4lt nur die Delta-\u00c4nderungen zwischen den vorherigen Monat und die aktuelle Version.<\/p>\n<p>Zus\u00e4tzlich zu den Sicherheitspatches f\u00fcr die Schwachstellen enthalten die Updates sogenannte 'defense-in-depth updates', um die Sicherheit zu verbessern.<\/p>\n<p>Die Updates lassen sich auch per <a href=\"https:\/\/www.catalog.update.microsoft.com\/Home.aspx\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Update Catalog<\/a> herunterladen. Die Updates f\u00fcr Windows RT 8.1 und Microsoft Office RT sind nur \u00fcber Windows Update erh\u00e4ltlich. Informationen zum Support-Zeitraum f\u00fcr Windows 10 finden sich im <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/13853\/windows-lifecycle-fact-sheet\" target=\"_blank\" rel=\"noopener noreferrer\">Windows Lifecycle Facts Sheet<\/a>.<\/p>\n<p>Von den nachfolgenden Schwachstellen wurde 6 als wichtig eingestuft, keine wurde bisher in der Praxis ausgenutzt. Allerdings wurden zwei neue Sicherheitsl\u00fccken, von denen eine alle unterst\u00fctzten Versionen des Windows-Betriebssystems betrifft und die andere Windows 7 und Server 2008, als aktiv genutzt gemeldet. Beide aktiv ausgenutzten Schwachstellen f\u00fchren zu einer Erh\u00f6hung der Berechtigung (Privileg Escalation), von denen eine (CVE-2019-1132) in der Win32k-Komponente liegt und einem Angreifer erlauben k\u00f6nnte, beliebigen Code im Kernelmodus auszuf\u00fchren.<\/p>\n<p>Die andere aktiv ausgenutzte Schwachstelle (CVE-2019-0880) liegt jedoch in der Art und Weise, wie<em> splwow64<\/em> (Thunking Spooler APIs) bestimmte Aufrufe behandelt, so dass ein Angreifer oder ein b\u00f6sartiges Programm seine Privilegien auf einem betroffenen System von einer niedrigen Integrit\u00e4t auf eine mittlere Integrit\u00e4t erh\u00f6hen kann.<\/p>\n<p>Die \u00f6ffentlich bekannten Fehler betreffen die Docker-Laufzeit, die SymCrypt Windows-Kryptobibliothek, Remote Desktop Services, Azure Automation, Microsoft SQL Server und Windows AppX Deployment Service (AppXSVC).<\/p>\n<p>Microsoft hat auch Updates f\u00fcr 14 kritische Schwachstellen ver\u00f6ffentlicht, und wie erwartet f\u00fchren alle zu Angriffen auf die Ausf\u00fchrung von Remote-Code und betreffen Microsoft-Produkte, die von Internet Explorer und Edge bis hin zu Windows Server DHCP, Azure DevOps und Team Foundation Servern reichen.<\/p>\n<h2>Critical Security Updates<\/h2>\n<p>Internet Explorer 11<br \/>\nChakraCore<br \/>\nMicrosoft Edge<br \/>\nWindows Server 2008 for 32-bit Systems Service Pack 2<br \/>\nWindows Server 2008 for 32-bit Systems Service Pack 2 (Server Core<br \/>\ninstallation)<br \/>\nWindows Server 2008 for Itanium-Based Systems Service Pack 2<br \/>\nWindows Server 2008 for x64-based Systems Service Pack 2<br \/>\nWindows Server 2008 for x64-based Systems Service Pack 2 (Server Core<br \/>\ninstallation)<br \/>\nWindows 7 for 32-bit Systems Service Pack 1<br \/>\nWindows 7 for x64-based Systems Service Pack 1<br \/>\nWindows Server 2008 R2 for Itanium-Based Systems Service Pack 1<br \/>\nWindows Server 2008 R2 for x64-based Systems Service Pack 1<br \/>\nWindows Server 2008 R2 for x64-based Systems Service Pack 1 (Server<br \/>\nCore installation)<br \/>\nWindows Server 2012<br \/>\nWindows Server 2012 (Server Core installation)<br \/>\nWindows 8.1 for 32-bit systems<br \/>\nWindows 8.1 for x64-based systems<br \/>\nWindows RT 8.1<br \/>\nWindows Server 2012 R2<br \/>\nWindows Server 2012 R2 (Server Core installation)<br \/>\nWindows 10 for 32-bit Systems<br \/>\nWindows 10 for x64-based Systems<br \/>\nWindows 10 Version 1607 for 32-bit Systems<br \/>\nWindows 10 Version 1607 for x64-based Systems<br \/>\nWindows 10 Version 1703 for 32-bit Systems<br \/>\nWindows 10 Version 1703 for x64-based Systems<br \/>\nWindows 10 version 1709 for 32-bit Systems<br \/>\nWindows 10 version 1709 for x64-based Systems<br \/>\nWindows 10 Version 1709 for ARM64-based Systems<br \/>\nWindows 10 Version 1803 for 32-bit Systems<br \/>\nWindows 10 Version 1803 for x64-based Systems<br \/>\nWindows 10 Version 1803 for ARM64-based Systems<br \/>\nWindows 10 Version 1809 for 32-bit Systems<br \/>\nWindows 10 Version 1809 for x64-based Systems<br \/>\nWindows 10 Version 1809 for ARM64-based Systems<br \/>\nWindows 10 Version 1903 for 32-bit Systems<br \/>\nWindows 10 Version 1903 for x64-based Systems<br \/>\nWindows 10 Version 1903 for ARM64-based Systems<br \/>\nWindows Server 2016<br \/>\nWindows Server 2016 (Server Core installation)<br \/>\nWindows Server, version 1803 (Server Core Installation)<br \/>\nWindows Server, version 1903 (Server Core Installation)<br \/>\nWindows Server 2019<br \/>\nWindows Server 2019 (Server Core installation)<br \/>\nMicrosoft Visual Studio 2010 Service Pack 1<br \/>\nMicrosoft Visual Studio 2012 Update 5<br \/>\nMicrosoft Visual Studio 2013 Update 5<br \/>\nMicrosoft Visual Studio 2015 Update 3<br \/>\nMicrosoft Visual Studio 2017<br \/>\nMicrosoft Visual Studio 2017 version 15.9<br \/>\nMicrosoft Visual Studio 2019 version 16.0<br \/>\nMicrosoft Visual Studio 2019 version 16.1<br \/>\nTeam Foundation Server 2010 SP1<br \/>\nTeam Foundation Server 2012 Update 4<br \/>\nTeam Foundation Server 2013 Update 5<br \/>\nTeam Foundation Server 2015 Update 4.2<br \/>\nTeam Foundation Server 2017 Update 3.1<br \/>\nTeam Foundation Server 2018 Update 1.2<br \/>\nTeam Foundation Server 2018 Update 3.2<br \/>\nASP.NET Core 2.1<br \/>\nASP.NET Core 2.2<br \/>\nMicrosoft .NET Framework 2.0 Service Pack 2<br \/>\nMicrosoft .NET Framework 3.0 Service Pack 2<br \/>\nMicrosoft .NET Framework 3.5<br \/>\nMicrosoft .NET Framework 3.5 AND 4.7.2<br \/>\nMicrosoft .NET Framework 3.5 AND 4.8<br \/>\nMicrosoft .NET Framework 3.5.1<br \/>\nMicrosoft .NET Framework 4.5.2<br \/>\nMicrosoft .NET Framework 4.6<br \/>\nMicrosoft .NET Framework 4.6\/4.6.1\/4.6.2<br \/>\nMicrosoft .NET Framework 4.6\/4.6.1\/4.6.2\/4.7\/4.7.1\/4.7.2<br \/>\nMicrosoft .NET Framework 4.8<br \/>\nAzure Automation<br \/>\nAzure DevOps Server 2019.0.1<br \/>\nMail and Calendar<\/p>\n<h2>Important Security Updates<\/h2>\n<p>Microsoft Excel 2010 Service Pack 2 (32-bit editions)<br \/>\nMicrosoft Excel 2010 Service Pack 2 (64-bit editions)<br \/>\nMicrosoft Excel 2013 RT Service Pack 1<br \/>\nMicrosoft Excel 2013 Service Pack 1 (32-bit editions)<br \/>\nMicrosoft Excel 2013 Service Pack 1 (64-bit editions)<br \/>\nMicrosoft Excel 2016 (32-bit edition)<br \/>\nMicrosoft Excel 2016 (64-bit edition)<br \/>\nMicrosoft Office 2010 Service Pack 2 (32-bit editions)<br \/>\nMicrosoft Office 2010 Service Pack 2 (64-bit editions)<br \/>\nMicrosoft Office 2013 RT Service Pack 1<br \/>\nMicrosoft Office 2013 Service Pack 1 (32-bit editions)<br \/>\nMicrosoft Office 2013 Service Pack 1 (64-bit editions)<br \/>\nMicrosoft Office 2016 (32-bit edition)<br \/>\nMicrosoft Office 2016 (64-bit edition)<br \/>\nMicrosoft Office 2016 for Mac<br \/>\nMicrosoft Office 2019 for 32-bit editions<br \/>\nMicrosoft Office 2019 for 64-bit editions<br \/>\nMicrosoft Office 2019 for Mac<br \/>\nMicrosoft Outlook 2010 Service Pack 2 (32-bit editions)<br \/>\nMicrosoft Outlook 2010 Service Pack 2 (64-bit editions)<br \/>\nMicrosoft Outlook 2013 Service Pack 1 (32-bit editions)<br \/>\nMicrosoft Outlook 2013 Service Pack 1 (64-bit editions)<br \/>\nMicrosoft Outlook 2016 (32-bit edition)<br \/>\nMicrosoft Outlook 2016 (64-bit edition)<br \/>\nMicrosoft Outlook for Android<br \/>\nMicrosoft SharePoint Enterprise Server 2013 Service Pack 1<br \/>\nMicrosoft SharePoint Enterprise Server 2016<br \/>\nMicrosoft SharePoint Foundation 2010 Service Pack 2<br \/>\nMicrosoft SharePoint Foundation 2013 Service Pack 1<br \/>\nMicrosoft SharePoint Server 2019<br \/>\nOffice 365 ProPlus for 32-bit Systems<br \/>\nOffice 365 ProPlus for 64-bit Systems<br \/>\nOutlook for iOS<br \/>\nMail and Calendar<br \/>\nMicrosoft Lync 2013 Service Pack 1 (32-bit)<br \/>\nMicrosoft Lync 2013 Service Pack 1 (64-bit)<br \/>\nMicrosoft Lync Basic 2013 Service Pack 1 (32-bit)<br \/>\nMicrosoft Lync Basic 2013 Service Pack 1 (64-bit)<br \/>\nSkype for Business 2016 (32-bit)<br \/>\nSkype for Business 2016 (64-bit)<br \/>\nSkype for Business 2016 Basic (32-bit)<br \/>\nSkype for Business 2016 Basic (64-bit)<br \/>\nMicrosoft Exchange Server 2010 Service Pack 3<br \/>\nMicrosoft Exchange Server 2013 Cumulative Update 23<br \/>\nMicrosoft Exchange Server 2016 Cumulative Update 12<br \/>\nMicrosoft Exchange Server 2016 Cumulative Update 13<br \/>\nMicrosoft Exchange Server 2019 Cumulative Update 1<br \/>\nMicrosoft Exchange Server 2019 Cumulative Update 2<br \/>\nMicrosoft SQL Server 2014 Service Pack 2 for 32-bit Systems (CU+GDR)<br \/>\nMicrosoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR)<br \/>\nMicrosoft SQL Server 2014 Service Pack 2 for x64-based Systems (CU+GDR)<br \/>\nMicrosoft SQL Server 2014 Service Pack 2 for x64-based Systems (GDR)<br \/>\nMicrosoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU+GDR)<br \/>\nMicrosoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR)<br \/>\nMicrosoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU+GDR)<br \/>\nMicrosoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR)<br \/>\nMicrosoft SQL Server 2016 for x64-based Systems Service Pack 1 (CU+GDR)<br \/>\nMicrosoft SQL Server 2016 for x64-based Systems Service Pack 1 (GDR)<br \/>\nMicrosoft SQL Server 2016 for x64-based Systems Service Pack 2 (CU+GDR)<br \/>\nMicrosoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR)<br \/>\nMicrosoft SQL Server 2017 for x64-based Systems (CU+GDR)<br \/>\nMicrosoft SQL Server 2017 for x64-based Systems (GDR)<br \/>\nAzure IoT Edge<br \/>\nMicrosoft Azure Kubernetes Service<br \/>\nMicrosoft.IdentityModel 7.0.0<\/p>\n<h2>Moderate Security Updates<\/h2>\n<p>Internet Explorer 9<br \/>\nInternet Explorer 10<\/p>\n<h2>Defense-in-Depth Updates<\/h2>\n<p>Microsoft Exchange Server 2013<br \/>\nMicrosoft Exchange Server 2016<br \/>\nMicrosoft Exchange Server 2019<\/p>\n<p><strong>\u00c4hnliche Artikel:<\/strong><br \/>\n<a href=\"https:\/\/borncity.com\/blog\/2019\/07\/03\/microsoft-office-patchday-2-juli-2019\/\">Microsoft Office Patchday (2. Juli 2019)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/blog\/2019\/07\/09\/microsoft-security-update-summary-9-juli-2019\/\">Microsoft Security Update Summary (9. Juli 2019)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/blog\/2019\/07\/10\/patchday-updates-fr-windows-7-8-1-server-9-juli-2019\/\">Patchday: Updates f\u00fcr Windows 7\/8.1\/Server (9. Juli 2019)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/blog\/2019\/07\/10\/patchday-windows-10-updates-9-juli-2019\/\">Patchday Windows 10-Updates (9. Juli 2019)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/blog\/2019\/07\/11\/patchday-microsoft-office-updates-9-juli-2019\/\">Patchday Microsoft Office Updates (9. Juli 2019)<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[English]Zum 9. Juli 2019 hat Microsoft zahlreiche Sicherheitsupdates f\u00fcr Windows-Clients und \u2013Server, f\u00fcr Office etc. freigegeben. Hier ein kompakter \u00dcberblick.<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[270,426,185,301],"tags":[4322,4315,3288],"class_list":["post-220325","post","type-post","status-publish","format-standard","hentry","category-office","category-sicherheit","category-update","category-windows","tag-office","tag-update","tag-windows-en"],"_links":{"self":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts\/220325","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/comments?post=220325"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts\/220325\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/media?parent=220325"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/categories?post=220325"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/tags?post=220325"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}