Microsoft has published the January 2021 security updates.
January 2021 Security Updates
The January 2021 security release consists of security updates for the following software:
- Microsoft Windows
- Microsoft Edge (EdgeHTML-based)
- Microsoft Office and Microsoft Office Services and Web Apps
- Microsoft Windows Codecs Library
- Visual Studio
- SQL Server
- Microsoft Malware Protection Engine
- .NET Core
- .NET Repository
- ASP .NET
- Azure
Please note the following information regarding the security updates:
- CVE-2020-0689 has been re-released. For further information see Security update for Secure Boot DBX: January 12, 2021.
- For information regarding enabling Windows 10, version 1909 features, please see Windows 10, version 1909 delivery options. Note that Windows 10, versions 1903 and 1909 share a common core operating system with an identical set of system files. They will also share the same security update KBs.
- Windows 10 updates are cumulative. The monthly security release includes all security fixes for vulnerabilities that affect Windows 10, in addition to non-security updates. The updates are available via the Microsoft Update Catalog.
- For information on lifecycle and support dates for Windows 10 operating systems, please see Windows Lifecycle Facts Sheet.
- A list of the latest servicing stack updates for each operating system can be found in ADV990001. This list will be updated whenever a new servicing stack update is released. It is important to install the latest servicing stack update.
- Updates for Windows RT 8.1 and Microsoft Office RT software are only available via Windows Update.
- In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features.
- Customers running Windows 7, Windows Server 2008 R2, or Windows Server 2008 need to purchase the Extended Security Update to continue receiving security updates. See 4522133 for more information.
The following CVEs have FAQs with additional information. Please note that this is not a complete list of CVEs for this release.
- CVE-2020-26870
- CVE-2021-1636
- CVE-2021-1637
- CVE-2021-1643
- CVE-2021-1644
- CVE-2021-1645
- CVE-2021-1647
- CVE-2021-1648
- CVE-2021-1656
- CVE-2021-1663
- CVE-2021-1669
- CVE-2021-1670
- CVE-2021-1672
- CVE-2021-1676
- CVE-2021-1677
- CVE-2021-1694
- CVE-2021-1696
- CVE-2021-1699
- CVE-2021-1707
- CVE-2021-1708
- CVE-2021-1711
- CVE-2021-1713
- CVE-2021-1714
- CVE-2021-1715
- CVE-2021-1716
- CVE-2021-1725
Known Issues
The following KBs contain information about known issues with the security updates. For a complete list of security update KBs, please see 20210112. For more information about Windows Known Issues, please see Windows message center (links to currently-supported versions of Windows are in the left pane).
KB Article Applies To 4598229 Windows 10, Version 1903, Windows Server, Version 1903, Windows 10, Version 1909, Windows Server, Version 1909 4598230 Windows 10, Version 1809, Windows Server 2019 4598242 Windows 10, Version 2004, Windows Server, Version 2004, Windows 10, Version 20H2, Windows Server, Version 20H2 4598275 Windows 8.1, Windows Server 2012 R2 (Security-only update) 4598278 Windows Server 2012 (Monthly Rollup) 4598279 Windows 7, Windows Server 2008 R2 (Monthly Rollup) 4598285 Windows 8.1, Windows Server 2012 R2 (Monthly Rollup) 4598287 Windows Server 2008 (Security-only update) 4598288 Windows Server 2008 (Monthly Rollup) 4598289 Windows 7, Windows Server 2008 R2 (Security-only update) 4598297 Windows Server 2012 (Security-only update)
Security Update Guide - Microsoft Security Response Center