Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
Overview
On Patch Tuesday, Microsoft addressed a record-breaking 974 vulnerabilities across its software, including two that are currently being exploited. The vulnerabilities include 723 in Windows, 111 in Office, 62 in SQL, and 22 in Developer Tools. Over 110 of these flaws are classified as critical, meaning they could allow attackers to gain significant control over affected systems. The fact that two of these vulnerabilities are actively exploited in the wild raises serious concerns for users and organizations using these products. It is crucial for users to apply the patches as soon as possible to protect their systems from potential attacks.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Windows, Office, Office 2016, SQL, Developer Tools
- Action Required: Users should apply the latest security updates provided by Microsoft for all affected products.
- Timeline: Newly disclosed
Original Article Summary
Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Of these, over 110 shortcomings have been assigned a critical severity rating.
Impact
Windows, Office, Office 2016, SQL, Developer Tools
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Users should apply the latest security updates provided by Microsoft for all affected products. Specific patch numbers were not mentioned, but updates can typically be found through Windows Update or the Microsoft Update Catalog.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Windows, Microsoft, Patch, and 1 more.