{"id":21359,"date":"2021-09-15T05:24:04","date_gmt":"2021-09-15T03:24:04","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=21359"},"modified":"2021-09-15T14:42:27","modified_gmt":"2021-09-15T12:42:27","slug":"microsoft-security-update-summary-14-september-2021","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2021\/09\/15\/microsoft-security-update-summary-14-september-2021\/","title":{"rendered":"Microsoft Security Update Summary (September 14, 2021)"},"content":{"rendered":"<p><img decoding=\"async\" style=\"margin: 0px 10px 0px 0px;\" title=\"Update\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2021\/06\/Update-01.jpg\" alt=\"Update\" align=\"left\" border=\"0\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2021\/09\/15\/microsoft-security-update-summary-14-september-2021\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]On September 14, Microsoft released security updates for Windows clients and servers, for Office, etc. &#8211; as well as for other products &#8211; were released. These include fixes for PrintNightmare as well as for the MSHTML vulnerability. Below is a compact overview of these updates released on Patchday.<\/p>\n<p><!--more--><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg07.met.vgwort.de\/na\/285d31409f8f40739e5408ec1a413895\" alt=\"\" width=\"1\" height=\"1\" \/>A list of the updates can be found on <a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\" target=\"_blank\" rel=\"noopener\">this Microsoft page<\/a>. Details about the update packages for Windows, Office, etc. are available in separate blog posts.<\/p>\n<h2>Notes on the updates<\/h2>\n<p>Windows 10 version 2004, 20H2 and 21H1 share a common core and have an identical set of system files. Therefore, the same security update will be delivered for these Windows 10 versions. Information on how to enable the features of Windows 10 version 1909 as well as 20H2, which is done through an Enablement Package update, can be found in <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/Windows-IT-Pro-Blog\/Windows-10-version-1909-delivery-options\/ba-p\/1002660\" target=\"_blank\" rel=\"noopener\">this tech community post<\/a>.<\/p>\n<p>All Windows 10 updates are cumulative. The monthly Patchday update includes all security fixes for Windows 10 and all non-security fixes through Patchday. In addition to vulnerability security patches, the updates include security enhancement measures. Microsoft is integrating the Servicing Stack Updates (SSUs) into the Latest Cumulative Updates (LCUs) for newer versions of Windows 10. A list of the latest SSUs can be found at <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/ADV990001\" target=\"_blank\" rel=\"noopener\">ADV990001<\/a>(although the list is not always up-to-date).<\/p>\n<p>Windows 7 SP1 is no longer supported as of January 2020. Only customers with a 2nd year ESU license (or bypasses) will still receive updates. With the current ESU bypass lets install the update. Updates can also be downloaded from the <a href=\"https:\/\/www.catalog.update.microsoft.com\/Home.aspx\" target=\"_blank\" rel=\"noopener\">Microsoft Update Catalog<\/a> . Updates for Windows RT 8.1 and Microsoft Office RT are only available through Windows Update.<\/p>\n<h2>Fixed vulnerabilities<\/h2>\n<p>The September 2021 security updates close vulnerabilities (60 CVEs, 3 of them critical) in Microsoft products. A list of all covered CVEs can be found on <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2021-Sep\" target=\"_blank\" rel=\"noopener\">this Microsoft page<\/a>. The vulnerability in MSHTML (see <a href=\"https:\/\/borncity.com\/win\/2021\/09\/14\/desaster-windows-mshtml-schwachstelle-cve-2021-40444-hoffentlich-kommt-heute-ein-patch\/\">Disaster Windows MSHTML vulnerability CVE-2021-40444, hopefully a patch will come today<\/a>) is said to have been patched. Furthermore, there is a fix for <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-26435\" target=\"_blank\" rel=\"noopener\">CVE-2021-26435<\/a> (Windows Scripting Engine Memory Corruption Vulnerability),\u00a0 <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-36965\" target=\"_blank\" rel=\"noopener\">CVE-2021-36965<\/a> (Windows WLAN AutoConfig Service Remote Code Execution Vulnerability), <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-38633\" target=\"_blank\" rel=\"noopener\">CVE-2021-38633<\/a>, <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-36963\" target=\"_blank\" rel=\"noopener\">CVE-2021-36963<\/a> (Windows Common Log File System Driver Elevation of Privilege Vulnerability) and the recurring fixed vulnerability <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-38671\" target=\"_blank\" rel=\"noopener\">CVE-2021-38671<\/a> (Windows Print Spooler Elevation of Privilege Vulnerability). Qualys has listed all the fixed vulnerabilities on <a href=\"https:\/\/blog.qualys.com\/vulnerabilities-threat-research\/2021\/09\/14\/microsoft-and-adobe-patch-tuesday-september-2021-microsoft-60-vulnerabilities-with-3-critical-adobe-61-vulnerabilities\" target=\"_blank\" rel=\"noopener\">this web page<\/a>.<\/p>\n<h2>Critical Security Updates<\/h2>\n<p>Windows 10 for 32-bit Systems<br \/>\nWindows 10 for x64-based Systems<br \/>\nWindows 10 Version 1607 for 32-bit Systems<br \/>\nWindows 10 Version 1607 for x64-based Systems<br \/>\nWindows 10 Version 1809 for 32-bit Systems<br \/>\nWindows 10 Version 1809 for ARM64-based Systems<br \/>\nWindows 10 Version 1809 for x64-based Systems<br \/>\nWindows 10 Version 1909 for 32-bit Systems<br \/>\nWindows 10 Version 1909 for ARM64-based Systems<br \/>\nWindows 10 Version 1909 for x64-based Systems<br \/>\nWindows 10 Version 2004 for 32-bit Systems<br \/>\nWindows 10 Version 2004 for ARM64-based Systems<br \/>\nWindows 10 Version 2004 for x64-based Systems<br \/>\nWindows 10 Version 20H2 for 32-bit Systems<br \/>\nWindows 10 Version 20H2 for ARM64-based Systems<br \/>\nWindows 10 Version 20H2 for x64-based Systems<br \/>\nWindows 10 Version 21H1 for 32-bit Systems<br \/>\nWindows 10 Version 21H1 for ARM64-based Systems<br \/>\nWindows 10 Version 21H1 for x64-based Systems<br \/>\nWindows 8.1 for 32-bit systems<br \/>\nWindows 8.1 for x64-based systems<br \/>\nWindows RT 8.1<br \/>\nWindows Server 2012<br \/>\nWindows Server 2012 (Server Core installation)<br \/>\nWindows Server 2012 R2<br \/>\nWindows Server 2012 R2 (Server Core installation)<br \/>\nWindows Server 2016<br \/>\nWindows Server 2016\u00a0 (Server Core installation)<br \/>\nWindows Server 2019<br \/>\nWindows Server 2019\u00a0 (Server Core installation)<br \/>\nWindows Server 2022<br \/>\nWindows Server 2022 (Server Core installation)<br \/>\nWindows Server, version 2004 (Server Core installation)<br \/>\nWindows Server, version 20H2 (Server Core Installation)<br \/>\nHEVC Video Extensions<br \/>\nMPEG-2 Video Extension<br \/>\nAzure Open Management Infrastructure<\/p>\n<h2>Important Security Updates<\/h2>\n<p>Microsoft 365 Apps for Enterprise for 32-bit Systems<br \/>\nMicrosoft 365 Apps for Enterprise for 64-bit Systems<br \/>\nMicrosoft Excel 2013 RT Service Pack 1<br \/>\nMicrosoft Excel 2013 Service Pack 1 (32-bit editions)<br \/>\nMicrosoft Excel 2013 Service Pack 1 (64-bit editions)<br \/>\nMicrosoft Excel 2016 (32-bit edition)<br \/>\nMicrosoft Excel 2016 (64-bit edition)<br \/>\nMicrosoft Office 2013 RT Service Pack 1<br \/>\nMicrosoft Office 2013 Service Pack 1 (32-bit editions)<br \/>\nMicrosoft Office 2013 Service Pack 1 (64-bit editions)<br \/>\nMicrosoft Office 2016 (32-bit edition)<br \/>\nMicrosoft Office 2016 (64-bit edition)<br \/>\nMicrosoft Office 2019 for 32-bit editions<br \/>\nMicrosoft Office 2019 for 64-bit editions<br \/>\nMicrosoft Office 2019 for Mac<br \/>\nMicrosoft Office Online Server<br \/>\nMicrosoft Office Web Apps Server 2013 Service Pack 1<br \/>\nMicrosoft SharePoint Enterprise Server 2016<br \/>\nMicrosoft SharePoint Foundation 2013 Service Pack 1<br \/>\nMicrosoft SharePoint Server 2019<br \/>\nMicrosoft Edge (Chromium-based)<br \/>\nMicrosoft Edge for Android<br \/>\nMicrosoft Visual Studio 2017 version 15.9 (includes 15.0 &#8211; 15.8)<br \/>\nMicrosoft Visual Studio 2019 version 16.11 (includes 16.0 &#8211; 16.10)<br \/>\nMicrosoft Visual Studio 2019 version 16.4 (includes 16.0 &#8211; 16.3)<br \/>\nMicrosoft Visual Studio 2019 version 16.7 (includes 16.0 &#8211; 16.6)<br \/>\nMicrosoft Visual Studio 2019 version 16.9 (includes 16.0 &#8211; 16.8)<br \/>\nVisual Studio Code<br \/>\nAccessibility Insights for Android<br \/>\nAccessibility Insights for Android Service &#8211; v2.0.0<br \/>\nAzure Sphere<br \/>\nMicrosoft Dynamics 365 Business Central 2020 Release Wave 2 &#8211; Update 17.10<br \/>\nMicrosoft Dynamics 365 Business Central 2021 Release Wave 1 &#8211; Update 18.5<\/p>\n<p><strong>Similar articles<br \/>\n<\/strong><a href=\"https:\/\/borncity.com\/win\/2021\/09\/08\/microsoft-office-patchday-7-september-2021\/\">Microsoft Office Patchday (September 7, 2021)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/09\/15\/microsoft-security-update-summary-14-september-2021\/\">Microsoft Security Update Summary (September 14, 2021)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/09\/15\/patchday-windows-10-updates-september-14-2021\/\">Patchday: Windows 10-Updates (September 14, 2021)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/09\/15\/patchday-windows-8-1-server-2012-updates-14-september-14-2021\/\">Patchday: Windows 8.1\/Server 2012 Updates (September 14, 2021)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/09\/15\/patchday-updates-fr-windows-7-server-2008-r2-14-september-2021\/\">Patchday: Updates for Windows 7\/Server 2008 R2 (September 14, 2021)<\/a><br \/>\nPatchday Microsoft Office Updates (September 14, 2021)<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]On September 14, Microsoft released security updates for Windows clients and servers, for Office, etc. &#8211; as well as for other products &#8211; were released. These include fixes for PrintNightmare as well as for the MSHTML vulnerability. Below is a &hellip; <a href=\"https:\/\/borncity.com\/win\/2021\/09\/15\/microsoft-security-update-summary-14-september-2021\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,580,22,2],"tags":[125,2674,69,195,194],"class_list":["post-21359","post","type-post","status-publish","format-standard","hentry","category-office","category-security","category-update","category-windows","tag-office","tag-patchday-9-2021","tag-security","tag-update","tag-windows"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/21359","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=21359"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/21359\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=21359"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=21359"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=21359"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}