Microsoft announced last week that it would not be releasing security updates in February. In fact, the company has canceled February updates altogether for the first time in Patch Tuesday history.
Microsoft said it will release the updates in March, which means several known security issues will remain unpatched. The first is a Windows security flaw discovered on February 3rd that affects SMB. The flaw affects Windows 8, Windows 10, and Windows Server.
Google a few days later published a security flawaffecting Windows, stating that Microsoft had been notified of the vulnerability 90 days earlier, but did nothing.
So for now we have mentioned two unpatched issues that attackers could exploit, but there is also Flash Player. Adobe released a new version of Flash Player (24.0.0.221) and while Google immediately released the updated version of Flash Player in Chrome, Microsoft Edge was not updated.
This means that the version of Flash in Edge is currently vulnerable to attacks targeting Adobe vulnerabilities.
The big problem is that users and administrators cannot upgrade Adobe Flash Player on their own unless Microsoft releases a patch for Flash.
But it seems that today Microsoft has gone the extra mile. The company has outdone itself and released the updated version of Flash Player for all systems that have Flash Player built-in.
As for the other security updates, they will be announced in the next scheduled monthly update on March 14, 2017.
Microsoft released security bulletin MS17-005 just a while ago.
MS17-005 : It is a Security update for Adobe Flash Player :
The company states:
February 21, 2017 — This security update resolves vulnerabilities in Adobe Flash Player if Flash Player is installed on any supported edition of Windows Server 2016, Windows Server 2012 R2, Windows Server 2012, Windows 10, Windows 10 Version 1511, Windows 10 Version 1607, Windows 8.1, or Windows RT 8.1.
Update KB4010250 is available through Windows Update and the Microsoft Update Catalog.
