#Patch Tuesday

[ follow ]
microsoft
ComputerWeekly.com
1 month ago
Information security

Patch Tuesday: Windows Server 2008 receives emergency security patch | Computer Weekly

Microsoft's latest Patch Tuesday in April 2024 addresses 155 vulnerabilities, including 3 critical ones and 145 important severity ones.
An emergency patch for the Proxy Driver Spoofing Vulnerability impacting Windows desktop and server OS was released for end-of-life versions like Windows Server 2008. [ more ]
Theregister
1 month ago
Information security

Microsoft security bypass bug said to be under exploit

Microsoft fixed 149 security flaws on Patch Tuesday.
A vulnerability, CVE-2024-26234, was actively exploited with a backdoor in Windows. [ more ]
Theregister
2 months ago
Information security

March Patch Tuesday fixes Hyper-V guest-host escape

61 CVE-tagged vulnerabilities in Microsoft's Patch Tuesday.
Two critical Hyper-V vulnerabilities, one RCE and one DOS. [ more ]
Zero Day Initiative
3 months ago
Information security

Zero Day Initiative - The February 2024 Security Update Review

Adobe released six patches addressing 29 CVEs, with fixes for Acrobat and Reader being prioritized due to critical-rated code execution bugs.
Microsoft released a patch for a 0-day discovered by the ZDI Threat Hunting Team. [ more ]
WIRED
3 months ago
Information security

Apple and Google Just Patched Their First Zero-Day Flaws of the Year

Google released Chrome 121 with fixes for 17 security issues, including three high-impact vulnerabilities.
Microsoft's January Patch Tuesday addressed nearly 50 bugs, including 12 remote code execution (RCE) flaws. [ more ]
ComputerWeekly.com
4 months ago
Information security

Windows Kerberos, Hyper-V vulns among January Patch Tuesday bugs | Computer Weekly

Microsoft has released 49 new patches addressing various vulnerabilities in its products, including two critical flaws in Windows Kerberos and Windows Hyper-V.
This is the second consecutive light Patch Tuesday release, with no zero-day or Exchange issues addressed.
The vulnerabilities in Windows Kerberos and Windows Hyper-V allow for security feature bypass and remote code execution, respectively, and require proximity to the internal network for exploitation. [ more ]
moremicrosoft
vulnerabilities
ComputerWeekly.com
2 months ago
Information security

March Patch Tuesday throws up two critical Hyper-V flaws | Computer Weekly

Two critical vulnerabilities in Windows Hyper-V were fixed, notably with a decrease in total fixed vulnerabilities from the previous month.
The slimline update this Patch Tuesday did not include any zero-day vulnerabilities or PoCs, leading to a moment of relative calm in the cybersecurity landscape. [ more ]
ComputerWeekly.com
5 months ago
Information security

Microsoft's Christmas present for cyber teams: no zero-days | Computer Weekly

Microsoft delivers a light Patch Tuesday update with only 34 CVEs listed, following a year of numerous critical vulnerabilities in its products and services.
Despite the light load, the update does include four new updates for critical CVEs and an AMD flaw that is close to zero-day territory. [ more ]
Theregister
6 months ago
Information security

Microsoft fixes security holes including 3 already exploited

Microsoft's November Patch Tuesday includes fixes for about 60 vulnerabilities, including three that have already been exploited in the wild.
The vulnerabilities include a Windows Desktop Manager elevation-of-privilege vulnerability, a privilege-escalation vulnerability in Windows Cloud Files Mini Filter Driver, and a vulnerability that allows bypassing Windows Defender SmartScreen.
These vulnerabilities are likely being exploited in conjunction with code execution bugs and users are advised to update quickly. [ more ]
morevulnerabilities
adobe
Theregister
4 months ago
Information security

January Patch Tuesday: New year, new Windows' bugs

Microsoft released 49 Windows security updates, including fixes for two critical-rated bugs.
There are four high-severity Chrome flaws in Microsoft Edge. [ more ]
Zero Day Initiative
5 months ago
Information security

Zero Day Initiative - The December 2023 Security Update Review

Apple released patches for iOS and iPadOS with eight CVEs, including two under active attack on older devices.
Adobe released patches for various software, covering 212 CVEs in total, with the majority in Experience Manager. [ more ]
moreadobe
[ Load more ]