You are currently viewing Microsoft Security /Cumulative Updates April Tuesday Patches

Microsoft Security /Cumulative Updates April Tuesday Patches

This Month update affects the Arab Republic of Egypt. The update supports the government’s daylight saving time change order for 2023.

This is April- Tuesday Microsoft Cumulative updates report | prepared by Hazem Mohamed:

Important Note: There is no anyone reported any issues related to this month’s updates till now.

Microsoft announcement regarding Windows clients: IMPORTANT Starting in April 2023, optional, non-security preview updates will release on the fourth Tuesday of the month. For more information.

The information gathered about April updates :

CVE
Microsoft’s ARPIL 2023 Tuesday Updates, Microsoft released patches to 97 vulnerabilities, including ONE zero-day CVE-2023-28252 (Windows Common Log File System Driver Elevation of Privilege Vulnerability)

  •  20 Elevation of Privilege Vulnerabilities
  • 8 Security Feature Bypass Vulnerabilities
  • 45 Remote Code Execution Vulnerabilities
  • 10 Information Disclosure Vulnerabilities
  • 9 Denial of Service Vulnerabilities
  • 6 Spoofing Vulnerabilities

For Windows Server 2016 has 66  CVEs : 6 Critical and 60 Important

Critical CVEs :

 

CVE-2023-28250
CVE-2023-28232
CVE-2023-28231
CVE-2023-28220
CVE-2023-28219
CVE-2023-21554
Important and Moderate CVEs:

 

CVE-2023-21729
CVE-2023-28308
CVE-2023-28307
CVE-2023-28306
CVE-2023-28305
CVE-2023-28302
CVE-2023-28298
CVE-2023-28297
CVE-2023-28293
CVE-2023-28256
CVE-2023-28278
CVE-2023-28255
CVE-2023-28254
CVE-2023-28253
CVE-2023-28276
CVE-2023-28275
CVE-2023-28252
CVE-2023-28273
CVE-2023-28249
CVE-2023-28272
CVE-2023-28271
CVE-2023-28248
CVE-2023-28247
CVE-2023-28269
CVE-2023-28268
CVE-2023-28244
CVE-2023-28267
CVE-2023-28266
CVE-2023-28243
CVE-2023-28241
CVE-2023-28240
CVE-2023-28238
CVE-2023-28236
CVE-2023-28237
CVE-2023-28228
CVE-2023-28229
CVE-2023-28227
CVE-2023-28225
CVE-2023-28224
CVE-2023-28223
CVE-2023-28222
CVE-2023-28221
CVE-2023-28218
CVE-2023-28217
CVE-2023-28216
CVE-2023-24931
CVE-2023-24929
CVE-2023-24887
CVE-2023-24928
CVE-2023-24886
CVE-2023-24927
CVE-2023-24885
CVE-2023-24926
CVE-2023-24884
CVE-2023-24925
CVE-2023-24883
CVE-2023-24924
CVE-2023-24912
CVE-2023-21769
CVE-2023-21727

KBs for Windows Servers 2016

1- KB5023788 (March-Servicing stack update)

2-      KB5025228 (Monthly Security Update)

KBs for Windows 10

·        KB5025221 (to versions 20H2-22H2-21H2)

·        KB5025228 (to version 1607)

·        KB5025229 (to version 1809)

·        KB5025234 (to based Systems & 1507)

  • KB5023788 (Servicing stack update)

 Before installing Security updates:

Microsoft strongly recommends you install the latest servicing stack update (SSU) for your operating system before installing the latest cumulative update (LCU). SSUs improve the reliability of the update process to mitigate potential issues while installing the LCU and applying Microsoft security updates.

the latest SSU (KB5023788) as mentioned …

  • 2-KB5025228 (Monthly security cumulative update Windows Server 2016):

 

Highlights:

  • This update addresses security issues for your Windows operating system.

Improvements:

This security update includes quality improvements. When you install this KB:

 

  • This update affects the Arab Republic of Egypt. The update supports the government’s daylight saving time change order for 2023.
  • This update addresses an issue that affects Microsoft Edge IE mode and pages that use predictive prerendering. Edge IE mode does not support predictive prerendering. Because of this, a page that uses prerendering will load as if it was not in use.
  • This update addresses compatibility issues that affect some printers. These printers use Windows Graphical Device Interface (GDI) printer drivers. These drivers do not completely adhere to GDI specifications.

If you installed earlier updates, only the new updates contained in this package will be downloaded and installed on your device.

For more information about security vulnerabilities, please refer to the new Security Update Guide website and the April 2023 Security Updates.

Known issues in this update :

Microsoft is not currently aware of any issues with this update.

To Download load any one of the above patches :

generally go to Microsoft Update Catalog and search about KB.

KB5023788 : https://www.catalog.update.microsoft.com/Search.aspx?q=KB5023788

KB5025228: https://www.catalog.update.microsoft.com/Search.aspx?q=KB5025228

References :

https://msrc.microsoft.com/update-guide/releaseNote/2023-Apr

https://msrc.microsoft.com/update-guide/

Best Regards ,

Hazem Mohamed

Senior IT Manager – BC&CS

hmohamed200@gmail.com

 

Update Article 13/04/2023 at 2:21PM

I have Install KBs for Windows 10 and 11, and the DST has been shown in time settings :

Update Article 27/04/2023 at 3:00PM

we always recommend to install security updates , but due to this month updates includes the government’s daylight saving time change order for 2023, 

we find the workaound to enable daylight saving feature if the patch failed to install for any reason…

***Important Note : this workaround already tested on Windows 10 22H2 and Windows Server 2016.

1- Go to any Windows Machine that already has the April patch ( for example Windows 10 or Windows server 2016).

2-  Exprot the below 2 registry keys by the below PowerShell commands (open powershell –> Run As Administrator .):

PS C:\WINDOWS\system32> reg export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\TimeZoneInformation d:\Win22H2-DaylightSaving-01.reg

 

reg export “HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Egypt Standard Time” d:\Win22H2-DaylightSaving-02-EST.reg

3-  copy those reg keys files to the machine that cannot install the April patch on it for any reason, and run the below powershell commands commands (Run As Administrator) :

must be go to the folder you already store the reg keys on it by cd command

reg import .\Win22H2-DaylightSaving-02-EST.reg

 

reg import .\Win22H2-DaylightSaving-01.reg

 

you can download ready reg keys files for Windows 10 22H2 and Windows Server 2016 from the below link :

https://drive.google.com/drive/folders/1uZIB2Rl6YNtkgEunm4yQmKzlQfBNZdv-?usp=sharing 

 

Go Luck and Have a nice weekend.

Best Regards,

Hazem Mohamed

Senior IT Manager – BC&CS

hmohamed200@gmail.com