Windows 10: Windows Security: time to patch these three zero-day vulnerabilities

Discus and support Windows Security: time to patch these three zero-day vulnerabilities in Windows 10 News to solve the problem; Microsoft released security updates for all client and server versions of Windows that it supports yesterday. Among the 30 or so security issues that... Discussion in 'Windows 10 News' started by GHacks, Feb 15, 2023.

  1. GHacks
    GHacks New Member

    Windows Security: time to patch these three zero-day vulnerabilities


    Microsoft released security updates for all client and server versions of Windows that it supports yesterday. Among the 30 or so security issues that each version of Windows is affected by are three zero-day vulnerabilities that are exploited already.

    Windows Security: time to patch these three zero-day vulnerabilities windows-security-updates-february-2023.png

    It is interesting to note that all three of the zero-day vulnerabilities have received a severity rating of important. Each version of Windows is also affected by critical vulnerabilities, but none of these critical issues seem to be exploited currently.

    Microsoft Publisher Security Features Bypass Vulnerability


    The first vulnerability that is exploited in the wild affects Microsoft Publisher. The ID is CVE-2023-21715, and it affects systems on which Publisher, a Microsoft Office application, is installed on. Microsoft specifies further that only Microsoft 365 Apps for Enterprise are affected by this.

    The exploit targets the recent change in macro use in Microsoft Office. Microsoft implemented a security feature in Office recently that blocks macros in documents that come from untrusted sources, including the Internet.

    The exploit may be used to bypass these macro protections, so that documents with malicious macros may still be used to attack Windows devices.

    An attacker would have to convince a user to run a specially crafted Office document on the target machine. It could be distributed via websites or through other means.

    Windows Graphics Component Remote Code Execution Vulnerability


    The second vulnerability, filed under CVE-2023-21823, is rated important as well. It is a remote code execution vulnerability in the Windows Graphics Component.

    Microsoft notes that an attacker who manages to exploit the issue may gain SYSTEM privileges on the target device. Microsoft's description lacks clarity, as it lists a number of affected products, including client and server versions of Windows, but also Microsoft Office for Android and iOS.

    One of the FAQ entries on the support page suggests that the issue could be related to OneNote, as Microsoft mentions OneNote for Android specifically there.

    Windows Common Log File System Driver Elevation of Privilege Vulnerability


    The third and final vulnerability, CVE-2023-23376, that is exploited already is an elevation of privileges vulnerability in the Windows Common Log File system driver.

    It has a rating of important and attackers could exploit the issue to gain SYSTEM privileges on attacked systems. All client and server versions of Windows are affected by the issue. Microsoft does not reveal how a potential attack scenario looks like.

    Closing Words

    Windows Home users and system administrators may want to address the issues immediately to protect devices against potential attacks. The severity rating of important suggests that Microsoft does not see the security issues as a major threat to a large percentage of the Windows population.

    Still, to be on the safe side, administrators may want to install the monthly security patches provided by Microsoft yesterday for all supported versions of Windows.

    Thank you for being a Ghacks reader. The post Windows Security: time to patch these three zero-day vulnerabilities appeared first on gHacks Technology News.

    read more...
     
    GHacks, Feb 15, 2023
    #1
  2. Brink Win User

    All Versions of Windows Are Vulnerable to a New Zero-Day Exploit

    Read more: All Versions of Windows Are Vulnerable to a New Zero-Day Exploit
     
    Brink, Feb 15, 2023
    #2
  3. Borg 386 Win User
    Borg 386, Feb 15, 2023
    #3
  4. Borg 386 Win User

    Windows Security: time to patch these three zero-day vulnerabilities

    Adobe readies emergency patch for Flash zero-day bug exploited in the


    Adobe readies emergency patch for Flash zero-day bug exploited in the wild

    Adobe readies emergency patch for Flash zero-day bug exploited in the wild | ZDNet
     
    Borg 386, Feb 15, 2023
    #4
Thema:

Windows Security: time to patch these three zero-day vulnerabilities

Loading...
  1. Windows Security: time to patch these three zero-day vulnerabilities - Similar Threads - Security patch three

  2. Its Groundhog Day at Microsoft! Vulnerability patched again

    in Windows 10 News
    Its Groundhog Day at Microsoft! Vulnerability patched again: Remember the movie Groundhog Day? Bull Murray plays a rather self-centered weatherman who finds himself in a time loop on Groundhog Day. Windows administrators may have similar feelings to Murray's in regards to vulnerability CVE-2021-43890. First patched in December 2021,...
  3. The Windows October 2023 security updates fix three 0-day vulnerabilities

    in Windows 10 News
    The Windows October 2023 security updates fix three 0-day vulnerabilities: The Windows Security Updates for October 2023 are now available. It is a big update for a number of reasons. First, because several Windows products have reached end of support. Second, because the update for Windows 11 includes new features, including Windows Copilot and the...
  4. NSA Reported Security Vulnerability Patch Hardware Dependent?

    in AntiVirus, Firewalls and System Security
    NSA Reported Security Vulnerability Patch Hardware Dependent?: My HP Compaq nc6120 runs Windows 10 1709 with all the quality updates currently offered by Windows Update. Reading about the recent NSA reported security vulnerability, I downloaded patch KB4534276 from http://www.catalog.update.microsoft.com/ and ran it; after about 10...
  5. Microsoft Exchange vulnerable to PrivExchange zero-day

    in Windows 10 News
    Microsoft Exchange vulnerable to PrivExchange zero-day: Microsoft Exchange 2013 and newer are vulnerable to a zero-day named "PrivExchange" that allows a remote attacker with just the credentials of a single lowly Exchange mailbox user to gain Domain Controller admin privileges with the help of a simple Python tool. Details about...
  6. A zero-day flaw in Windows 10 reportedly discovered, patch will land soon

    in Windows 10 News
    A zero-day flaw in Windows 10 reportedly discovered, patch will land soon: According to reports, a security researcher has discovered an unpatched vulnerability in the Windows 10 operating system. The security researcher reportedly revealed the vulnerability on Twitter. It’s a zero-day flaw that exists in Windows 10 and it could allow an attacker...
  7. Spectre Intel CPU Security Vulnerability Patch - Performance Questions

    in AntiVirus, Firewalls and System Security
    Spectre Intel CPU Security Vulnerability Patch - Performance Questions: Does the Intel patch for Spectre on a 6th Gen Core i5 Desktop CPU have any distinguishable performance hit for gaming, streaming, media playback, video editing, or photo editing? I heard there's a performance hit (so I've been avoiding the patch) but on newer processors it...
  8. Adobe readies emergency patch for Flash zero-day bug exploited in the

    in AntiVirus, Firewalls and System Security
    Adobe readies emergency patch for Flash zero-day bug exploited in the: Adobe readies emergency patch for Flash zero-day bug exploited in the wild Adobe has told users that an emergency patch is being prepared for a Flash zero-day vulnerability being exploited in the wild which can give attackers complete control. On Tuesday, the tech...
  9. Emergency Flash Player patch fixes zero-day critical flaw

    in AntiVirus, Firewalls and System Security
    Emergency Flash Player patch fixes zero-day critical flaw: Adobe Systems has released an emergency patch for Flash Player in order to fix a critical vulnerability that attackers are already taking advantage of. The vulnerability, tracked as CVE-2016-7855 in the Common Vulnerabilities and Exposures database, is a use-after-free...
  10. Kaspersky Lab discovers Silverlight zero-day vulnerability

    in Windows 10 News
    Kaspersky Lab discovers Silverlight zero-day vulnerability: Kaspersky Lab has discovered a dangerous zero-day vulnerability in Silverlight, potentially placing millions of users at risk. In a blog post on Wednesday, the cybersecurity firm said the vulnerability would allow an attacker to gain full access to a compromised computer...