Today is Patch Tuesday for June 2018, so Microsoft is releasing a number of security updates for all supported Windows versions. Here is the list of updates released today for Windows 10 users.
The updates do not include any new features, but they include a number of bug fixes. The following updates were released.
Windows 10 April 2018 Update version 1803
KB4284835 (OS Build 17134.112) comes with the following change log
- Provides protections from an additional subclass of speculative execution side channel vulnerability known as Speculative Store Bypass (CVE-2018-3639). These protections aren't enabled by default. For Windows client (IT pro) guidance, follow the instructions in KB4073119. For Windows Server guidance, follow the instructions in KB4072698. Use this guidance document to enable mitigations for Speculative Store Bypass (CVE-2018-3639) in addition to the mitigations that have already been released for Spectre Variant 2 (CVE-2017-5715) and Meltdown (CVE-2017-5754).
- Addresses an issue in which the 2017 and 2018 versions of Intuit QuickBooks can't run in multi-user mode on Windows 10 1803 devices. Users will now be offered Windows 10, version 1803.
- Adds support for the SameSite cookie web standard to Microsoft Edge and Internet Explorer.
- Addresses an issue with Internet Explorer that prevents it from using an updated version of location services.
- Addresses an issue that causes certain games to fail to show dialogs when connected to monitors that support interlaced display formats.
- Addresses an issue with the brightness controls on some laptops after updating to the Windows 10 April 2018 Update.
- Addresses a reliability issue in which the GameBar may fail to launch.
- Addresses an issue where firmware updates cause devices to go into BitLocker recovery mode when BitLocker is enabled, but Secure Boot is disabled or not present. This update prevents firmware installation on devices in this state. Administrators can install firmware updates by:
- Temporarily suspending BitLocker.
- Immediately installing firmware updates before the next OS startup.
- Immediately restarting the device so that BitLocker doesn’t remain in the suspended state.
- Addresses an issue that caused the system to start up to a black screen. This issue occurs because previous updates to the Spring Creators Update were incompatible with specific versions of PC tune-up utilities after installation.
- Security updates to Internet Explorer, Microsoft Edge, Microsoft scripting engine, Windows Desktop Bridge, Windows apps, Windows shell, Windows kernel, Windows Server, Windows storage and filesystems, Windows wireless networking, remote code execution, and Windows virtualization and kernel.
Windows 10 Fall Creators Update version 1709
KB4284819 (OS Build 16299.492)
- Provides protections from an additional subclass of speculative execution side channel vulnerability known as Speculative Store Bypass (CVE-2018-3639). These protections aren't enabled by default. For Windows client (IT pro) guidance, follow the instructions in KB4073119. For Windows Server guidance, follow the instructions in KB4072698. Use this guidance document to enable mitigations for Speculative Store Bypass (CVE-2018-3639) in addition to the mitigations that have already been released for Spectre Variant 2 (CVE-2017-5715) and Meltdown (CVE-2017-5754).
- Includes additional performance improvements.
- Addresses an issue in Microsoft Edge that causes incorrect responses to XML requests.
- Adds support for the SameSite cookie web standard to Microsoft Edge and Internet Explorer.
- Addresses an issue with Internet Explorer that prevents it from using an updated version of location services.
- Addresses an issue where firmware updates cause devices to go into BitLocker recovery mode when BitLocker is enabled, but Secure Boot is disabled or not present. This update prevents firmware installation on devices in this state. Administrators can install firmware updates by:
- Temporarily suspending BitLocker.
- Immediately installing firmware updates before the next OS startup.
- Immediately restarting the device so that BitLocker doesn’t remain in the suspended state.
- Security updates to Internet Explorer, Microsoft Edge, Microsoft scripting engine, Windows Desktop Bridge, Windows apps, Windows shell, Windows storage and filesystems, Windows app platform and frameworks, Windows virtualization and kernel, Windows wireless networking, and Windows Server.
Windows 10 Creators Update version 1703
KB4284874 (OS Build 15063.1155)
- Provides support to control usage of Indirect Branch Prediction Barrier (IBPB) on some AMD processors (CPUs) for mitigating CVE-2017-5715, Spectre Variant 2 when switching from user context to kernel context. (See AMD Architecture Guidelines for Indirect Branch Control and AMD Security Updates for more details). For Windows client (IT pro) guidance, follow the instructions in KB4073119. Use this guidance document to enable IBPB on some AMD processors (CPUs) for mitigating Spectre Variant 2 when switching from user context to kernel context.
- Provides protections from an additional subclass of speculative execution side channel vulnerability known as Speculative Store Bypass (CVE-2018-3639). These protections aren't enabled by default. For Windows client (IT pro) guidance, follow the instructions in KB4073119. Use this guidance document to enable mitigations for Speculative Store Bypass (CVE-2018-3639) in addition to the mitigations that have already been released for Spectre Variant 2 (CVE-2017-5715) and Meltdown (CVE-2017-5754).
- Includes additional performance improvements.
- Addresses a mobile-only issue where enterprise files could be saved as personal files even though the Windows Information Protection policy is enabled on the device.
- Addresses an issue where firmware updates cause devices to go into BitLocker recovery mode when BitLocker is enabled, but Secure Boot is disabled or not present. This update prevents firmware installation on devices in this state. Administrators can install firmware updates by:
- Temporarily suspending BitLocker.
- Immediately installing firmware updates before the next OS startup.
- Immediately restarting the device so that BitLocker doesn’t remain in the suspended state.
- Addresses an issue where booting with Unified Write Filter (UWF) turned on may lead to stop error 0xE1 in embedded devices, particularly when using a USB hub.
- Increased the Internet Explorer cookie limit from 50 to better align with industry standards.
- Security updates to Internet Explorer, Microsoft Edge, Microsoft scripting engine, Windows Desktop Bridge, Windows apps, Windows Server, Windows wireless networking, Windows storage and filesystems, Windows app platform and frameworks, and Windows virtualization and kernel.
Windows 10 Anniversary Update version 1607
- Provides protections from an additional subclass of speculative execution side channel vulnerability known as Speculative Store Bypass (CVE-2018-3639). These protections aren't enabled by default. For Windows client (IT pro) guidance, follow the instructions in KB4073119. For Windows Server guidance, follow the instructions in KB4072698. Use this guidance document to enable mitigations for Speculative Store Bypass (CVE-2018-3639) in addition to the mitigations that have already been released for Spectre Variant 2 (CVE-2017-5715) and Meltdown (CVE-2017-5754).
- Includes additional performance improvements.
- Addresses an issue where booting with Unified Write Filter and a connected USB hub may lead to stop error E1.
- Addresses an issue where firmware updates cause devices to go into BitLocker recovery mode when BitLocker is enabled but Secure Boot is disabled or not present. This update prevents firmware installation on devices in this state. Administrators can install firmware updates by:
- Temporarily suspending BitLocker.
- Immediately installing firmware updates before the next OS startup.
- Immediately restarting the device so that BitLocker doesn’t remain in the suspended state.
- Permits a band-capable disk that has only one partition, which is an MSR partition, to convert to a dynamic disk.
- Increased the Internet Explorer cookie limit from 50 to better align with industry standards.
- Security updates to Internet Explorer, Microsoft Edge, Microsoft scripting engine, Windows Desktop Bridge, Windows apps, Windows datacenter networking, Windows wireless networking, Windows Server, Windows virtualization and kernel, and Windows app platform and frameworks.
Finally, the initial version of Windows 10 is getting KB4284860 (OS Build 10240.17889) with the same fixes.
You can get these updates using Windows Update in Settings. Alternatively, you can get them from the Microsoft Update Catalog and install them offline.
Source: Microsoft.
Support us
Winaero greatly relies on your support. You can help the site keep bringing you interesting and useful content and software by using these options:
Thanks sergey!
You’re welcome mate.
After KB4284835 was installed I discovered any Macrium backups were crashed (ditto Windows image backup, now dated / defunct) and the only quick effective solution was to disable / hide it via wushowhide. diagcab. (This was also reported on Microsoft’s community posts to which I offered my fix).
I also unticked the config box to de-enable Windows updates, hence the above KB..835 cannot be forced in again.
This was the only issue I had noted but only having it installed for a week.
[I usually backup weekly (Win10 Home, but have two clones of this that I like to keep at less frequent backups].
BUT .. skimming your details I note my protections are therefore (very?) compromised.
So just what to do? How do I report this to Microsoft and/or find solutions / fixes when I have ‘shut the update door?’
Better fixes must be somewhere, surely.