Microsoft has patched 5 zero-day leaks during yesterday's Patch Tuesday. Two of them were vulnerabilities in Windows that were actively attacked before a patch became available. In total 12 security updates for 30 vulnerabilities in Internet Explorer, Edge, the .NET Framework, Windows, Skype for Business and Microsoft Lync were released.

Three patched vulnerabilities in respectively Internet Explorer, the .NET Framework and Windows 10 were already publicly disclosed before Microsoft released the updates. It's unknown whether these zero-days were already actively attacked. Two zero-days were found in all supported versions of Windows but while these weren't publicly disclosed before they were actively attacked.
The discovered vulnerabilities in Windows are in the kernel-mode driver that allowed an attacker with access to the computer to elevate his rights and can gain full control over the system. These vulnerabilities were discovered by Russian antivirus company Kaspersky Lab and American security company FireEye.
Five of the 12 patches were marked as critical which means they are for vulnerabilities whose exploitation could allow code execution without user interaction.















