Η Microsoft was released today the monthly updates security στο πλαίσιο του καθιερωμένου Patch Tuesday. This month, the company patched 112 security holes in several productfrom Microsoft Edge to Windows WalletService.
This month's updates also include a fix for a Windows 0day online.
This 0day (CVE-2020-17087) was revealed on October 30 by the security teams of Google Project Zero and TAG. Η Google ανέφερε ότι για την ευπάθεια κυκλοφορεί ήδη exploit που χρησιμοποιείται μαζί με ένα 0day του Chrome zero-day για να στοχεύσει χρήστες των Windows 7 and Windows 10.
According to Microsoft Security Communication for CVE-2020-17087, 0day is located in the Windows kernel and affects all supported versions of the Windows operating system. That is, all versions after Windows 7 as well as all versions of Windows Server.
But in addition to Windows zero-day, the company fixed 111 other vulnerabilities. Among them are 24 security vulnerabilities that allow remote code execution (RCE) attacks on applications such as Excel, Microsoft Sharepoint, Microsoft Exchange Server, Windows Network File System, Windows GDI +, Windows printing spooler service and Microsoft Teams.
Of course as always it is recommended to update your system immediately.