Anyone have a clue as to how to update curl on 1800 computers with Bigfix?. I believe the latest is 8.4.0 but I see no fixlet tin my console. Help! thanks.
If you mean the copy of curl that ships with Windows, the update is included in the Nov 2023 and later Cumulative Updates. Tracking down the information for this is…weird.
https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2023-38545
UPDATE: Microsoft has included version 8.4.0 of curl.exe in Windows updates released on November 14, 2023 for currently supported, on-premise versions of Windows clients and servers. See the Security Updates table in this CVE for the applicable Windows update KB numbers. Windows security updates are cumulative, so future updates will include curl 8.4.0 or higher.
At the bottom of that page there’s a spreadsheet of KB numbers.
However… neither ‘CVE-2023-38545’ nor ‘curl’ is mentioned in the Release Notes for those specific KBs, at least as far as I could find. But I can see by running ‘curl --version’ that my systems have been updated to the 8.4.0 version.