Security News > 2023 > March > Microsoft Rolls Out Patches for 80 New Security Flaws — Two Under Active Attack
Microsoft's Patch Tuesday update for March 2023 is rolling out with remediations for a set of 80 security flaws, two of which have come under active exploitation in the wild.
The two vulnerabilities that have come under active attack include a Microsoft Outlook privilege escalation flaw and a Windows SmartScreen security feature bypass.
The disclosure also comes as the U.S. Cybersecurity and Infrastructure Security Agency added the two flaws to the Known Exploited Vulnerabilities catalog and announced a new pilot program that aims to warn critical infrastructure entities about "Vulnerabilities commonly associated with known ransomware exploitation."
Also closed out by Microsoft are a number of critical remote code execution flaws impacting HTTP Protocol Stack, Internet Control Message Protocol, and Remote Procedure Call Runtime.
Other notable mentions include patches for four privilege escalation bugs identified in the Windows Kernel, 10 remote code execution flaws affecting Microsoft PostScript and PCL6 Class Printer Driver, and a WebView2 spoofing vulnerability in the Edge browser.
Elsewhere, Microsoft also closed out two information disclosure flaws in Microsoft OneDrive for Android, one spoofing vulnerability in Office for Android, one security bypass bug in Microsoft OneDrive for iOS, and one privilege escalation issue in OneDrive for macOS. Rounding off the list are patches for two high-severity vulnerabilities in the Trusted Platform Module 2.0 reference library specification that could lead to information disclosure or privilege escalation.
News URL
https://thehackernews.com/2023/03/microsoft-rolls-out-patches-for-80-new.html
Related news
- Microsoft Fixes AI, Cloud, and ERP Security Flaws; One Exploited in Active Attacks (source)
- Security? We've heard of it: How Microsoft plans to better defend Windows (source)
- Phishing-as-a-Service "Rockstar 2FA" Targets Microsoft 365 Users with AiTM Attacks (source)
- Update your OpenWrt router! Security issue made supply chain attack possible (source)
- CERT-UA Warns of Phishing Attacks Targeting Ukraine’s Defense and Security Force (source)
- Microsoft enforces defenses preventing NTLM relay attacks (source)
- Hackers Use Microsoft MSC Files to Deploy Obfuscated Backdoor in Pakistan Attacks (source)
- Cross-Domain Attacks: A Growing Threat to Modern Security and How to Combat Them (source)
- Severe Security Flaws Patched in Microsoft Dynamics 365 and Power Apps Web API (source)
- Hackers use FastHTTP in new high-speed Microsoft 365 password attacks (source)