Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • Patch Tuesday July 2018 current page
Link copied

Patch Tuesday July 2018

Jul 11, 2018
Author:
400x400 Linkedin X Profile
Phantom Labs™
BeyondTrust
Blog banner default
Patch Tuesday July 2018
400x400 Linkedin X Profile
Phantom Labs™
BeyondTrust

patch tuesday

Welcome back to this month’s Patch Tuesday. Microsoft has patched 53 vulnerabilities this month, with 17 rated critical and 34 rated important. The majority of the critical vulnerabilities reside in Microsoft’s Chakra engine that parses Jscript. The Chakra engine is a core component of Microsoft’s web browsers.

Internet Explorer and Edge

Microsoft’s browsers received a host of critical fixes this month. Four vulnerabilities in the Chakra engine could lead to remote code execution when parsing malicious Jscript content. Microsoft has indicated that these vulnerabilities are likely to be targeted for an exploit in the wild, and are a priority to patch for workstation systems.

Kernel

As usual, the Windows kernel itself received a number of fixes. The vulnerabilities had an impact of information disclosure that could lead to elevation of privilege. These vulnerabilities revolved around the mishandling of objects in memory.

Windows DNS

Unlike last month’s wormable remote code execution bug in Windows DNS server’s DNSAPI, this vulnerability only causes Denial of Service by sending a malformed DNS response. This can still have a devastating impact on a network infrastructure and should be taken seriously. Microsoft rates this vulnerability as important, with exploitation less likely.

Office

Office received the usual amount of attention it gets every patch Tuesday. None of the office vulnerabilities were rated as critical. Attackers leveraging these vulnerabilities would be able to remotely execute code with privileges equal to that of the current user, obtain sensitive information on the system, and elevate privileges. Be sure to verify the source of Office files before opening them to help protect against these kinds of vulnerabilities.

Adobe Flash Player

Adobe Flash Player received two fixes this month. One was an out-of-bounds read that discloses potentially sensitive information to an attacker, and the other was a type confusion bug that allowed for arbitrary code execution. The two vulnerabilities are rated Important and Critical, respectively. Neither of these vulnerabilities are actively being exploited in the wild.

.Net Framework

Microsoft’s .Net Framework has not received an update since May, so it was due. The framework received fixes for multiple vulnerabilities. These vulnerabilities had impacts of allowing an attacker to gain elevated privileges, remote code execution, and bypass security features. Microsoft rates these vulnerabilities as important.

Latest Posts
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
  • How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    May 21, 2026 How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    Blog
    5m
  • Cybersecurity as a Boardroom Priority for Major African TelCos
    May 12, 2026 Cybersecurity as a Boardroom Priority for Major African TelCos
    Blog
    8m
  • Geopolitics and Cybersecurity: Why Attackers Go After Identities and Privileged Access First
    May 11, 2026 Geopolitics and Cybersecurity: Why Attackers Go After Identities and Privileged Access First
    Blog
    4m
Related
  • It’s Time to Increase Your IT Service Desk’s Value
    May 25, 2018 It’s Time to Increase Your IT Service Desk’s Value
    Blog
    1m
  • How Phishing Uses Our Strengths Against Us
    Jan 22, 2020 How Phishing Uses Our Strengths Against Us
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.