Microsoft Ends 2016 With Patch Tuesday Windows 10 Fix

Microsoft has fixed a Wi-Fi connection issue that has reportedly been plaguing Windows 10 users, in December’s Patch Tuesday security update.

The last update of 2016 sees Redmond delivering a total of 12 security bulletins, six of which are rated as ‘critical’ and six as ‘important.’

Microsoft admitted last week that some Windows 10 users had trouble connecting to the Internet. It advised users to reboot, but not shutdown their computers, to resolve the issue.

Patch Before Partying

Meanwhile back to the bulletins, it seems that one of the most noteworthy bulletins to apply before any festival celebrations can begin, is MS16-144 for Internet Explorer. At least according to Amol Sarwate, director of vulnerability research at Qualys.

Microsoft Edge browser is also patched with MS16-145, which again fixes three vulnerabilities.

Microsoft Office also gets updated (MS16-148) to prevent a user being compromised without any user interaction.

“December continues a long running trend with Microsoft’s products where the majority of bulletins (6) are dominated by remote code execution (RCE) vulnerabilities, which predominantly affect consumer applications,” noted Adam Nowak, lead engineer at Rapid7.

“These types of vulnerabilities are difficult to distinguish as they typically lure users to visit/open an e-mail, webpage or multimedia, which makes use of specially crafted content,” he warned. “Upon viewing this content (emails, webpages, etc.) a bad actor can execute malicious code and take complete control of an affected system with the same privileges of the user, this action is known as remote code execution.

“Unfortunately, consumers remain the single largest attack vector and should pay attention to the following critical remote code execution bulletins: MS16-144, MS16-145, MS16-146, MS16-147 and MS16-154.”

But he also advised system admins pay attention to critical remote code execution bulletins MS16-146 and MS16-147.

Ongoing Battle

There are no signs of any slowdown in the number of vulnerabilities being discovered as 2016 winds down to a close.

Earlier this week Symantec warned that Microsoft’s PowerShell scripting language and shell framework is increasingly being used to create malware and can be exploited as an attack vector by hackers.

And Proofpoint has also noted a new malvertising attack targeting Windows and Android devices. That attack on internet routers ensnares victim networks though legitimate websites hosting unknowingly distributed malicious advertisements.

Quiz: Are you a security pro?

Tom Jowitt

Tom Jowitt is a leading British tech freelancer and long standing contributor to Silicon UK. He is also a bit of a Lord of the Rings nut...

Recent Posts

OpenAI Hit By Austrian Complaint Over ChatGPT ‘False Data’

Rights group argues ChatGPT tendency to generate false information on individuals violates GDPR data protection…

24 hours ago

EU Designates Apple’s iPad OS As DMA ‘Gatekeeper’

European Commission says Apple's iPadOS is 'gatekeeper' due to large number of businesses 'locked in'…

1 day ago

Beating the Barbarians in the Cloud

As the cloud continues to be an essential asset for all businesses, developing and maintaining…

1 day ago

Austria Conference Calls For Controls On ‘Killer Robots’

Internatinal conference in Vienna calls for controls on AI-powered autonomous weapons to ensure humans remain…

1 day ago

Taiwanese Chip Giant Exits China Mainland

Major Taiwan chip assembly and test firm KYEC to sell Jiangsu subsidiary, exit mainland China…

1 day ago

Deepfakes: More Than Skin Deep Security

As deepfake technology continues to blur the lines between reality and deception, businesses and individuals…

1 day ago