Patch Tuesday: Microsoft Catches Four Zero-Day Vulnerabilities

Date:

Share:


Every second Tuesday of the month, Microsoft releases a bundle of fixes for Windows. This Tuesday brings four zero-day vulnerabilities, two high-criticality vulnerabilities, and some sister patches from Adobe.

On Patch Tuesday, which Microsoft calls “Update Tuesday,” other large software companies like Adobe release major security fixes. It’s a time to launch updates across corporate networks, and it occurs during mid-morning Pacific Standard Time to keep admins and users from having to scramble at the beginning of the week or the following day.

Patch Tuesday is a useful reminder for admins to ensure their Microsoft security updates are up to date.

Attackers exploited four zero-day vulnerabilities

The four vulnerabilities attackers have already taken advantage of are:

  • CVE-2024-43491: a flaw in Servicing Stack in Windows 10, version 1507 that opens up Optional Components to vulnerabilities previously thought to be mitigated. Later versions of Windows 10 are not affected. The September 2024 Servicing stack update and the September 2024 Windows security update address this flaw.
  • CVE-2024-38226: a bypass vulnerability in Microsoft Publisher.
  • CVE-2024-38217: a technique by which an attacker could evade Mark of the Web security alerts.
  • CVE-2024-38014: a vulnerability that creates improper privilege management and could grant attackers unwanted privileges.

SEE: IBM’s Chris Hockings is optimistic about the safety of the internet in the next five years due to passkeys and defenses against deepfakes.

Two vulnerabilities fell under NIST’s ‘critical’ category

The National Vulnerability Database’s Common Vulnerability Scoring System assigns a “critical” rating to vulnerabilities that meet a certain threshold of severity in their prioritization system. These vulnerabilities, which require immediate attention, include CVE-2024-43491, as listed above, and CVE-2024-38220, which involves an elevation of privilege vulnerability in the Azure Stack Hub.

In total, fixes for 79 flaws were deployed in September’s Update Tuesday.

Adobe released its own monthly security updates

Adobe released its own handful of fixes for Photoshop, Cold Fusion, Acrobat Reader, Illustrator, Premiere Pro, After Effects, Audition, and Media Encoder.



Source link

━ more like this

Apple’s AI glasses will experiment with plenty of designs and colors

Apple is finally stepping into the smart glasses space. For this, the company is asking an important question: Would you actually wear these...

Apple’s foldable iPhone might steer clear of a delay, after all

For a brief moment, it looked like Apple’s long-awaited foldable iPhone had hit a classic case of “almost, but not quite.” Reports of...

OpenAI says Elon Musk is orchestrating a last-minute ‘legal ambush’ before trial

The feud between Elon Musk and OpenAI is getting even more contentious as the two sides get ready for trial later this month....

Ukrainian forces have successfully killed or seriously wounded over 1.3m Russians – London Business News | Londonlovesbusiness.com

Ukraine’s military has claimed that Russian forces have suffered more than 1.3 million personnel losses since the start of Moscow’s full-scale invasion, according...

Four Ukrainian POWs executed by Russian troops in Kharkiv – London Business News | Londonlovesbusiness.com

Ukrainian prosecutors have launched a significant war crimes investigation following grave allegations that Russian troops shot and killed four Ukrainian prisoners of war...
spot_img