Microsoft fixes actively attacked leak in Internet Explorer and Edge

Yesterday's Microsoft Patch Tuesday fixed nearly 50 vulnerabilities in Internet Explorer, Edge, Windows, Silverlight, Office and Exchange. In total 13 updates were released of which 6 were marked critical.

myce-microsoft-patch

The 7 other patches are marked important by the software giant. Two vulnerabilities are so-called zero-days, vulnerabilities that were known or attacked before an update is released. A vulnerability in both Internet Explorer and Edge was actively attacked and allowed attackers to steal data from the browser. Microsoft hasn't disclosed what kind of data could be obtained.

A vulnerability in Windows also allowed attackers to retrieve information, this issue was revealed before an update was released but Microsoft reports it hasn't been actively attacked. The majority of the vulnerabilities were in Microsoft Office which saw 13 vulnerabilities fixed. Edge and Internet Explorer saw 12 and 10 respectively of which some are exploited the same vulnerability that existed in both browsers.

Microsoft also fixed a leak in Windows that allowed an attacker with physical access to the computer to elevate his rights. In order to do so, an attacker had to connect the computer to a malicious Wifi hotspot or insert a mobile broadband adapter after which it became possible to execute code on the locked computer.

On most computer the updates are automatically downloaded and installed.

No posts to display