Microsoft was released today the monthly ones security updates στο πλαίσιο του καθιερωμένου Patch Tuesday. Αυτό το μήνα, η εταιρεία επιδιόρθωσε 112 κενά ασφαλείας σε πολλά προϊόντα, από τον Microsoft Edge μέχρι το Windows WalletService.
This month's updates also include a fix for a Windows 0day released in the Internet.
This 0day (CVE-2020-17087) was revealed on October 30 by the security teams of Google Project Zero and TAG. Google said the vulnerability was already being exploited and used alongside a 0day Chrome zero-day to target Windows 7 and Windows 10 users.
According to Microsoft Security Communication for CVE-2020-17087, 0day is located in the Windows kernel and affects all supported versions of the Windows operating system. That is, all versions after Windows 7 as well as all versions of Windows Server.
But in addition to the Windows zero-day, the company also patched 111 other vulnerabilities. Among them are 24 vulnerabilities that allow remote code execution (RCE) attacks on applications such as Excel, Microsoft Sharepoint, Microsoft Exchange Server, the Windows Network File System, the Windows GDI+ component, the Windows printing spooler service and also Microsoft Teams.
Of course as always it is recommended to update your system immediately.