Microsoft patched 6 zero-day vulnerabilities in Windows 10
If you are using Windows operating system, you should immediately update the patch Microsoft sent on June 8. According to Microsoft, six zero-day vulnerabilities are being exploited by hackers.
The most severe vulnerability (CVE-2021-33742) allows malicious websites to attack computers via Internet Explorer and other Microsoft programs. Microsoft Edge will also be affected if running in Internet Explorer mode.
Google's risk analysis team discovered the vulnerability last week. Shane Huntley, a member of the group, said it appeared to be developed by a commercial criminal organization for clients in the Middle East or Western Europe.
In addition, there are two other zero-day vulnerabilities (CVE-2021-31955 and 31956) that were used in conjunction with Chrome browser bugs in the wave of targeted attacks against various companies in April. However, at the end of April, the Chrome vulnerabilities were patched.
The two zero-day vulnerabilities CVE-2021-31199 and 31201 appear to be used in conjunction with a bug in the Adobe Reader program, which was patched by Adobe in May. The Adobe Reader vulnerability allows attackers to break into the system. , then thanks to a Microsoft vulnerability, an attacker can 'escalate privileges' to take full control.
The last zero-day vulnerability (CVE-2021-33739) is also a privilege escalation vulnerability. Microsoft did not disclose many details, but only revealed that it can be used after an attacker enters the system through phishing or other forms.
Obviously, Microsoft considers these zero-day vulnerabilities very dangerous because the company patched both Windows 7, Windows 8.1 and Windows 10. Windows 7 officially stopped supporting from January 2020 and will not receive updates. No more security, though Microsoft has quietly addressed the worst bugs of the operating system in the last few Patch Tuesday updates.
You should read it
- Instructions for creating the fastest Microsoft account
- Microsoft Office is now Microsoft 365. Here's how you could get it for free
- Microsoft will also have smart watches
- How to Become a Microsoft MVP
- 11 best tips to get started with Microsoft Loop
- Link Download Microsoft Word 2019
- Link download Microsoft Teams 1.3.00.3564
- 15 interesting features to use in Microsoft 365
May be interested
- Microsoft rewards $ 250,000 for any talent that discovers the new Meltdown and Specter vulnerabilitiesin the effort to protect users from meltdown and specter vulnerabilities, microsoft has decided to launch a 'bounty hunt' program with extremely lucrative expenses for anyone who finds new security flaws. and reveal them to microsoft.
- There is a Windows error that Microsoft can't fix forever, so a third party has to fix itthe windows bug with code cve-2021-34484 has been patched by microsoft before, but it is still not really complete, so 0patch has to be patched again.
- Detects 'long-standing' security vulnerabilities in Microsoft Officesecurity firm bkav on july 22 has warned that a microsoft office vulnerability has been quietly exploited since 2009.
- Microsoft fixes 8 critical vulnerabilitieson june 13, microsoft issued eight security patches for vulnerabilities in windows operating systems, internet explorer, windows media player and office software.
- Symantec patched vulnerabilities in antivirus softwareyesterday (may 30), software vendor symantec patched the flaw in its corporate antivirus product line (english version), which was discovered nearly a week ago. the gap is on
- Update KB5013943 fixes screen flickering and problems with .NET apps on Windows 11a series of issues have been fixed and a series of vulnerabilities have been patched in microsoft's windows 11 update kb5013493 and patch tuesday may 2022.
- Microsoft released a patch for 75 critical vulnerabilities on Windows 7 / 8.1 / 10, asking users to installmicrosoft has released a cumulative update that fixes 75 new vulnerabilities (including 15 extremely important vulnerabilities) found in windows for windows 10, windows 7, and windows 8.1 users.
- Microsoft has not patched security issues in IE8 for 7 monthsaccording to security company zero day initiative, internet explorer 8 browser has appeared a security hole for more than half a year, but microsoft almost never bothered to fix this error.
- KB4482887 update patched the Specter vulnerability, but it caused problems for some Windows 10 gamescode cumulative update kb4482887 for windows 10 1809 builds released a few days ago is causing a series of negative issues related to graphics processing performance in many different games.
- Microsoft has patched the critical vulnerability on Android Remote Desktop applicationthis vulnerability is currently monitored with cve-2019-1108 identifiers, and dangerous ratings at 'important'.