Security News > 2021 > January > January 2021 Patch Tuesday: Microsoft plugs Defender zero-day RCE
Microsoft has plugged 83 CVEs, including a Microsoft Defender zero-day.
One of the latter - a zero-day RCE affecting Microsoft Defender antivirus - is being exploited in the wild, but Microsoft didn't reveal more about these attacks.
"This bug in the Microsoft Malware Protection Engine may already be patched on your system as the engine auto-updates as needed. However, if your systems are not connected to the Internet, you'll need to manually apply the patch," Trend Micro Zero Day Initiative's Dustin Childs commented.
Among the critical flaws fixed on this January 2021 Patch Tuesday by Microsoft are five Remote Procedure Call runtime RCEs.
The rest of the patched flaws affect a wide variety of Microsoft solutions, including the Bot Framework SDK, Hyper-V, Microsoft Office, SharePoint, Windows Bluetooth, Windows CSC Service, and so on.
For January 2021 Patch Tuesday, SAP has released 10 new security notes and updated 7 previously released ones.
News URL
http://feedproxy.google.com/~r/HelpNetSecurity/~3/qb6ZXdq2XV0/
Related news
- Microsoft November 2024 Patch Tuesday fixes 4 zero-days, 91 flaws (source)
- Microsoft November 2024 Patch Tuesday fixes 4 zero-days, 89 flaws (source)
- Microsoft December 2024 Patch Tuesday fixes 1 exploited zero-day, 71 flaws (source)
- Microsoft slips Task Manager and processor count fixes into Patch Tuesday (source)
- Microsoft holds last Patch Tuesday of the year with 72 gifts for admins (source)
- Patch Tuesday: Microsoft Patches One Actively Exploited Vulnerability, Among Others (source)
- Microsoft SharePoint RCE bug exploited to breach corporate network (source)
- Synology Urges Patch for Critical Zero-Click RCE Flaw Affecting Millions of NAS Devices (source)
- November 2024 Patch Tuesday forecast: New servers arrive early (source)
- Microsoft fixes actively exploited zero-days (CVE-2024-43451, CVE-2024-49039) (source)