Security News > 2021 > February > Microsoft Issues Patches for In-the-Wild 0-day and 55 Others Windows Bugs

Microsoft Issues Patches for In-the-Wild 0-day and 55 Others Windows Bugs
2021-02-15 03:58

Microsoft on Tuesday issued fixes for 56 flaws, including a critical vulnerability that's known to be actively exploited in the wild.

The most critical of the flaws is a Windows Win32k privilege escalation vulnerability that allows attackers with access to a target system to run malicious code with elevated permissions.

"This zero-day is a new vulnerability which caused by win32k callback, it could be used to escape the sandbox of Microsoft browser or Adobe Reader on the latest Windows 10 version," DBAPPSecurity researchers said.

Lastly, the Windows maker released a set of fixes affecting its TCP/IP implementation - consisting of two RCE flaws and one denial of service vulnerability - that it said could be exploited with a DoS attack.

"Customers might receive a blue screen on any Windows system that is directly exposed to the internet with minimal network traffic. Thus, we recommend customers move quickly to apply Windows security updates this month."

To install the latest security updates, Windows users can head to Start > Settings > Update & Security > Windows Update or by selecting Check for Windows updates.


News URL

http://feedproxy.google.com/~r/TheHackersNews/~3/3tPrz5HM4Ys/microsoft-issues-patches-for-in-wild-0.html

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 725 810 4723 4728 3648 13909