Microsoft Patch Tuesday: 97 Windows Vulns, 1 Exploited Zero-Day By Orbit Brain January 10, 2023 0 530 views Cyber Security News Residence › Endpoint SafetyMicrosoft Patch Tuesday: 97 Home windows Vulns, 1 Exploited Zero-DayBy Ryan Naraine on January 10, 2023TweetMicrosoft’s safety patching machine hummed into overdrive Tuesday with the discharge of fixes for at the least 97 documented software program vulnerabilities, together with a zero-day that’s already been exploited to flee the browser sandbox.The zero-day, flagged by researchers at anti-malware firm Avast, was exploited in reside assaults to raise privileges and escape a browser’s sandbox mitigation.As has develop into customary, Microsoft is stingy with particulars on the vulnerability or the assaults. An advisory from Redmond marks the CVE-2023-21674 flaw within the “Exploitation Detected” class however the firm didn’t launch IOCs or any knowledge to assist defenders hunt for indicators of compromise.“An attacker who efficiently exploited this vulnerability may achieve SYSTEM privileges,” Microsoft mentioned, noting that the bug exists within the Home windows Superior Native Process Name (ALPC) part.Microsoft additionally known as consideration to CVE-2023-21549, a privilege escalation subject within the Home windows SMB Witness Service, warning that technical particulars on the vulnerability are publicly out there. To take advantage of this vulnerability, an attacker may execute a specifically crafted malicious script which executes an RPC name to an RPC host. This might lead to elevation of privilege on the server.An attacker who efficiently exploited this vulnerability may execute RPC capabilities which might be restricted to privileged accounts solely, Microsoft added.The January batch of patches fixes code execution, denial-of-service and elevation of privilege flaws in a variety of WIndows OS and system elements.Microsoft documented main safety issues in its flagship Workplace productiveness suite, .Web Core and Visible Studio Code, Microsoft Trade Server, Home windows Print Spooler, Home windows Defender and Home windows BitLocker.The Microsoft patches come on the identical day software program maker Adobe rolled out fixes for at the least 29 safety vulnerabilities in a variety of enterprise-facing merchandise. Probably the most outstanding replace, for the extensively deployed Adobe Acrobat and Reader software program, fixes critical-severity flaws that expose Home windows and macOS customers to code execution assaults. Video messaging big Zoom additionally launched patches for a number of safety vulnerabilities that expose each Home windows and macOS customers to malicious hacker assaults. The vulnerabilities, within the enterprise-facing Zoom Rooms product, might be exploited in privilege escalation assaults on each Home windows and macOS platforms.Associated: Adobe Plugs Safety Holes in Acrobat, Reader Software programAssociated: Zoom Patches Excessive Threat Flaws on Home windows, MacOS PlatformsAssociated: ICS Patch Tuesday Debuts With Warnings From Siemens, SchneiderGet the Each day Briefing Most CurrentMost LearnMicrosoft Patch Tuesday: 97 Home windows Vulns, 1 Exploited Zero-DayIntel Provides TDX to Confidential Computing Portfolio With Launch of 4th Gen Xeon ProcessorsAdobe Plugs Safety Holes in Acrobat, Reader Software programZoom Patches Excessive Threat Flaws on Home windows, MacOS Platforms2023 ICS Patch Tuesday Debuts With 12 Safety Advisories From Siemens, SchneiderVulnerability in Fashionable JsonWebToken Open Supply Challenge Results in Code ExecutionGitHub Introduces Automated Vulnerability Scanning CharacteristicPyPI Customers Focused With PoweRAT MalwareIowa’s Largest Metropolis Cancels Lessons On account of Cyber AssaultHow Will a Recession Will Have an effect on CISOs?In search of Malware in All of the Incorrect Locations?First Step For The Web’s subsequent 25 years: Including Safety to the DNSTattle Story: What Your Laptop Says About YouBe in a Place to Act Via Cyber Situational ConsciousnessReport Exhibits Closely Regulated Industries Letting Social Networking Apps Run Rampant2010, A Nice 12 months To Be a Scammer.Do not Let DNS be Your Single Level of FailureMethods to Establish Malware in a BlinkDefining and Debating Cyber WarfareThe 5 A’s that Make Cybercrime so EngagingMethods to Defend In opposition to DDoS AssaultsSafety Budgets Not in Line with ThreatsAnycast – Three Causes Why Your DNS Community Ought to Use ItThe Evolution of the Prolonged Enterprise: Safety Methods for Ahead Pondering OrganizationsUtilizing DNS Throughout the Prolonged Enterprise: It’s Dangerous EnterpriseSecurityWeek Podcast anti-malware antivirus CVE-2023-21549 CVE-2023-21674 endpoint detection and response malware Microsoft msrc mstic open source passivetotal patch tuesday riskiq windows defender windows vulnerability zero day attack zero-day Orbit Brainhttp://orbitbrain.com/ Orbit Brain is the senior science writer and technology expert. Our aim provides the best information about technology and web development designing SEO graphics designing video animation tutorials and how to use software easy ways and much more. Like Best Service Latest Technology, Information Technology, Personal Tech Blogs, Technology Blog Topics, Technology Blogs For Students, Futurism Blog.
‘Schoolyard Bully’ Android Trojan Targeted Facebook Credentials of 300,000 UsersIntroducing the Cyber Security News ‘Schoolyard Bully’ Android Trojan Targeted Facebook Credentials of 300,000 Users.... December 1, 2022 Cyber Security News
Morocco Detains Frenchman Wanted in US Over Cybercrime: Police SourceIntroducing the Cyber Security News Morocco Detains Frenchman Wanted in US Over Cybercrime: Police Source.... August 1, 2022 Cyber Security News
Zoom Patches Serious macOS App Vulnerabilities Disclosed at DEF CONIntroducing the Cyber Security News Zoom Patches Serious macOS App Vulnerabilities Disclosed at DEF CON.... August 16, 2022 Cyber Security News
US Charges Six in Operation Targeting 48 DDoS-for-Hire WebsitesIntroducing the Cyber Security News US Charges Six in Operation Targeting 48 DDoS-for-Hire Websites.... December 15, 2022 Cyber Security News
Zoom Patches High Risk Flaws on Windows, MacOS PlatformsIntroducing the Cyber Security News Zoom Patches High Risk Flaws on Windows, MacOS Platforms.... January 11, 2023 Cyber Security News
Bishop Fox Releases Open Source Cloud Hacking Tool ‘CloudFox’Introducing the Cyber Security News Bishop Fox Releases Open Source Cloud Hacking Tool ‘CloudFox’.... September 15, 2022 Cyber Security News