Interestana
Home/News/Microsoft Patches Record 974 Vulnerabilities, Two Exploited Zero-Days
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Microsoft Patches Record 974 Vulnerabilities, Two Exploited Zero-Days

Microsoft Patches Record 974 Vulnerabilities, Two Exploited Zero-Days

Microsoft released an unprecedented number of security patches on Tuesday, addressing a record-breaking 974 vulnerabilities across its extensive software ecosystem. This significant update, part of its regular Patch Tuesday cycle, included fixes for two critical zero-day vulnerabilities that had already been actively exploited by malicious actors in the wild. The sheer volume of patches underscores the ongoing challenges in securing complex software environments and the persistent threat landscape faced by users and organizations worldwide.

The disclosed vulnerabilities span various Microsoft products, with Windows bearing the brunt of the security issues. Specifically, 723 flaws were identified and patched within the Windows operating system. Beyond Windows, the update also addressed 111 vulnerabilities in Microsoft Office and Office 2016, indicating continued security concerns for its widely used productivity suite. Furthermore, 62 vulnerabilities were resolved in SQL, Microsoft's relational database management system, and 22 flaws were fixed in Developer Tools, which are essential for software creation. The company's proactive patching efforts aim to mitigate potential exploitation of these weaknesses.

Among the 974 vulnerabilities patched, over 110 have been classified with a critical severity rating. This designation means that these flaws, if exploited, could lead to severe consequences, such as complete system compromise, unauthorized data access, or denial-of-service attacks, often without requiring user interaction. The inclusion of two actively exploited zero-day flaws is particularly concerning. Zero-day vulnerabilities are those for which no patch or fix is publicly available when they are first discovered and exploited, giving attackers a significant advantage. Microsoft's rapid response to patch these exploited flaws highlights the urgency and potential impact of such discoveries.

This record-breaking patch release signifies a substantial effort by Microsoft to bolster the security posture of its products. The company's commitment to addressing such a large number of vulnerabilities, especially those actively being exploited, is crucial for protecting its vast user base. The scale of this update also serves as a reminder for IT professionals and end-users to prioritize timely application of security patches to defend against emerging threats and maintain the integrity of their systems and data. The ongoing discovery and remediation of such a high volume of flaws suggest a continuous arms race between software vendors and cyber adversaries.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next