Both updates (Windows and Office) are required?

0

Let's say I have a Windows 7 with Microsoft Office 2010. And I want to patch the vulnerability CVE-2017-0199.

The following article from Microsoft says that you need to install these 2 KB in my case (as I have this software):

  • Microsoft Office 2010 (KB3141538) 64-Bit Edition
  • Windows 7 x64 (KB4015546)

Windows explanation of CVE-2017-0199

The question is: should I install both patches? Or installing one of the above already solves the vulnerability for my system? I can't find any information about this. I'm interested in a kind of technical explanation to the question.

user3139207

Posted 2017-06-29T13:42:40.760

Reputation: 11

Answers

0

Should I install both patches?

You need to install KB3141538 and instead of KB4015546 you should installed KB4022719.

If you are not willing to install the KB4022719 you should install KB4022722. KB4015546 is from April, while you could install that, you would still be vulerable to the exploits fixed in May and June.

Or installing one of the above already solves the vulnerability for my system?

CVE-2017-0199 is a vulerability against Office.

I'm interested in a kind of technical explanation to the question.

You should install all available Office patches and install the Security Monthly Quality Rollup every month. The primary reason is, the exploit that made WannaCrypt possible, was fixed 2 months before the malware was even released. The linked vulerability in question was fixed released back in April, which means you have been vulerable to that exploit, for over 2 months.

Ramhound

Posted 2017-06-29T13:42:40.760

Reputation: 28 517

You should verify you have the current monthly rollup installed, if its already installed, then you have been patched. I didn't bother to link to the May monthly rollup for obvious reasons, its an old patch, which has been superseded by the June monthly rollup. – Ramhound – 2017-06-29T14:23:58.260