Six 0-Days Lead Microsoft’s August 2024 Patch Push
ID: 2edf194c-adf7-554a-b14b-58265ac1a3ca
STIX ID: report--2edf194c-adf7-554a-b14b-58265ac1a3ca
Feed Name: Krebs on Security
Microsoft released updates covering at least 90 vulnerabilities this month, including six zero-days that are being actively exploited — several local privilege escalation flaws that can yield SYSTEM privileges, an RCE in Edge when running Internet Explorer Mode, a Mark-of-the-Web bypass used in exploit chains, and an RCE in Microsoft Project tied to disabled macro warnings; Adobe also issued 11 bulletins fixing 71 vulnerabilities. Administrators are advised to apply patches promptly but cautiously (back up/imaging recommended) and monitor vendor and community resources for post-patch issues.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
