Skip to main content

Microsoft Patch Tuesday - March

Microsoft has released 17 updates to address 140 vulnerabilities, 47 of which were regarded as critical in Microsoft software.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Microsoft has released 17 updates to address 140 vulnerabilities, 47 of which were regarded as critical in Microsoft software.

Threat details

Exploitation of some of these vulnerabilities could allow a remote attacker to take control of an affected system. Users and administrators are encouraged to review Microsoft Security Bulletins MS17-006 through MS17-023 and apply the necessary updates.

Of this month’s release, those products containing critical vulnerabilities include Internet Explorer, Edge, Hyper-V, Windows PDF Library, Microsoft SMB Server, Uniscribe, Microsoft Graphics Component, Adobe Flash Player and Microsoft Windows.

Critical rated bulletins include:

Cumulative Security Update for Internet Explorer (MS17-006)
Cumulative Security Update for Microsoft Edge (MS17-007)
Security Update for Windows Hyper-V (MS17-008)
Security Update for Microsoft Windows PDF Library (MS17-009)
Security Update for Microsoft Windows SMB Server (MS17-010)
Security Update for Microsoft Uniscribe (MS17-011)
Security Update for Microsoft Windows (MS17-012)
Security Update for Microsoft Graphics Component (MS17-013)
Security Update for Adobe Flash Player (MS17-023)


Remediation steps

Type Step

Ensure patches are prioritised and rolled out highest risk first at the earliest available opportunity.

Relevant logs and other audit trails should be inspected for any indication of access via disclosed and known 0-day vulnerabilities that could have happened prior to patch application.

Additional mitigation should be sought to protect devices from future 0-day releases such as these, for example limiting access to devices from untrusted locations, disabling automatic loading of Flash material, strict mail filters with blocks in place to prevent certain non-required file types from being allowed onto the estate etc.

Good privilege controls restricting users to the lowest level of access required can prove an effective mitigation strategy, thereby seriously reducing the potential impact.

Ensure staff awareness is rolled out and refreshed to ensure staff are informed about the dangers of malicious websites and attachments.

 


Last edited: 17 February 2020 11:35 am