July 2019 Patch Tuesday Commentary, Chris Goettl, Director of Security Solutions at Ivanti

Ivanti director makes a comment on Microsoft’s Tuesday patch for Windows OS, Office Suite, Exchange Server, and more….
Lock on cyber background - Security Buyer

Share this article:

Microsoft has released an update for everything including the kitchen smart sink! Ok, maybe not for sinks, but there are updates for the Windows OS, Office, .Net, SQL, VSTS and an Advisory for Microsoft Exchange Server! There are also updates for the following development binaries: Azure IoT Edge, Azure Kubernetes Service, Azure Automation, Azure DevOps Server, ASP .Net Core, .Net Core and Chakra Core. It is quite the line-up.
Microsoft resolved a total of 77 unique CVEs this month including two zero-days that have been reported in attacks in the wild and six public disclosures.
The first exploited vulnerability (CVE-2019-0880) is an Elevation of Privilege exploit in splwow64 affecting Windows 8.1, Server 2012 and later operating systems. If exploited, an attacker can elevate their privilege level from a low to a medium-integrity. Once they have elevated their privilege level, an attacker could exploit another vulnerability to allow them to execute code.
The second exploited vulnerability (CVE-2019-1132) is also an Elevation of Privilege exploit. In this case the vulnerability is in Win32k and affects Windows 7, Server 2008 and Server 2008 R2. While an attacker would have to gain log-on access to the system to execute the exploit, the vulnerability, if exploited, would allow the attacker to take full control of the system.
Mozilla released updates for Firefox and Firefox, ESR resolving 21 vulnerabilities and 10 vulnerabilities respectively. Both are rated as critical and include vulnerabilities that could lead to information disclosure, sandbox escapes and remote code execution.
Oracle is releasing its Critical Patch Update next week on Tuesday, so expect updates from all your favourite middleware and Java.
This is a good time to bring up development tools. As the industry continues the shift toward DevOps and integrating with development binaries like Java, there are new considerations that you need to account for in managing the vulnerabilities in your environment. Java 11 changed the paradigm. There is no longer a JRE and a JDK. With Java 8 applications, a developer would build the application using the JDK and when the application was deployed to a system it required Java JRE to run. Each quarter when Oracle would release an update, the application did not require a change, but you needed to update the JRE instance to remove vulnerabilities. With Java 11, the JRE components are built right into the application. So, as Oracle releases Java 11 updates resolving security vulnerabilities, a developer will need to update their version of the JDK and build the application again to include the new JRE components if any were vulnerable.
Microsoft released updates for several development tools including .Net Core and ASP .Net Core this month that similarly need to update the SDK component, then build the application and redistribute to resolve the vulnerabilities. Other examples of development binaries include Apache Struts, ChakraCore, ASP.NET CORE, Open Enclave SDK and many others.

About Security Buyer

Security Buyer is the leading authority in global security content, delivering expert news, in-depth articles, exclusive interviews, and industry insights across print, digital, and event platforms. Published 10 times a year, the magazine is a trusted resource for professionals seeking updates and analysis on the latest developments in the security sector.

To submit an article, or for sponsorship opportunities, please contact our team below.

Rebecca Spayne Picture

Rebecca Spayne

Group Managing Editor

Georgina Turner Picture

Georgina Turner

Sales Manager

Afua Akoto Picture

Afua Akoto

Marketing Manager

Related News

Ai Solution of the year - securitybuyer.com

Have your say: vote for AI Solution of the Year

Voting is open for AI Solution of the Year at the Security Buyer Readers’ Awards 2026, with readers invited to select their winner
Access control of the year - securitybuyer.com

Have you voted for Access Control Solution of the Year?

Voting is open for Access Control Solution of the Year at the Security Buyer Readers’ Awards 2026, with readers invited
PaxLock Pro2 - securitybuyer.com

Paxton officially launches PaxLock Pro2

Paxton the security technology manufacturer has launched a brand-new re-engineered PaxLock which is built to protect straight
KentixONE data centre - securitybuyer.com

Data centre security with KentixONE

Prior1 develops container data centers to meet the highest security and energy efficiency standards. Their containers require
Chubbsafes - securitybuyer.com

Chubbsafes explores certified storage for jewellery and precious metals

Chubbsafes, part of Gunnebo Safe Storage, has launched a new technical discussion guide examining when certified
Mercury trends report - securitybuyer.com

New Mercury Research Finds Growing Cybersecurity Gap

2026 Trends in Access Controllers Report finds interoperability, cloud connectivity and AI are reshaping long-term controller strategies.
Chris Carroll - securitybuyer.com

Comelit-PAC Promotes Chris Carroll as Sales Director

Comelit-PAC has appointed Chris Carroll as Sales Director, following an 18 year career with the company, seeing him progress
Jason Bezuidenhout - securitybuyer.com

Zygal Appoints Jason Bezuidenhout

Zygal has appointed Jason Bezuidenhout as Chief Revenue Officer (CRO), strengthening its leadership team as the company continues
Eun-Kyung-Hong_- securitybuyer.com

How AI Manages Mixed Surveillance Workloads

Eun-Kyung Hong, HDD Product Manager at Toshiba Electronics Europe GmbH discusses AI optimisation in mixed surveillance workloads
ASSA ABLOY - securitybuyer.com

ASSA ABLOY Door Group highlights importance of BS 8214:2026

ASSA ABLOY Door Group is supporting Fire Door Safety Week 2026 by raising awareness of the latest update to BS 8214:2026
Scroll to Top