Microsoft fixes 33 vulnerabilities in the Edge browser, Windows, Internet Explorer and Office

Microsoft yesterday released 6 updates that in total fix 33 vulnerabilities in Windows, Office, Internet Explorer,  the Edge browser and Sharepoint Server. Of the 33 vulnerabilities 4 of them were zero-day leaks.

new-microsoft-logo

Three of the updates were marked 'critical' by Microsoft. This means that the attacker could execute random code on the computer without too much user interaction such as visiting a hacked or malicious website.

Fourteen fixed vulnerabilities were for Internet Explorer and one of the leaks was already disclosed before Microsoft released an update but wasn't actively exploited yet. The other two critical updates fix leaks in Windows.

Three updates for WIndows, Office, the Edge browser and Sharepoint Server were marked as 'important'. Through these leaks an attacker could elevate privileges on the system, gain access to data or execute random code but in order to achieve that required more interaction of the user, such as opening a specially prepared file.

Three of the patched leaks, in Trusted Boot, Windows and Sharepoint were disclosed before the updates were released, but weren't actively exploited.

Most users will automatically receive the updates through Windows Update.

No posts to display