Patch Tuesday fixes for 62 security blanks

Its monthly security updates - γνωστές και σαν Patch Tuesday - κυκλοφόρησαν με διορθώσεις σε 62 κενά ασφαλείας. Ανάμεσα σε αυτά υπάρχει (επιτέλους) και η επιδιόρθωση του 0day released via Twitter last month.

The security updates released for this month affect many Microsoft products: Windows, Microsoft Edge, Explorer, ASP.NET, .NET Framework, ChakraCore Edge, Player, Microsoft.Data.OData, various Microsoft Office services and Web applications.

Of all the 62 repairs, the most important is the CVE-2018-8440. The security loophole allows malware or an attacker that already exists on a system to gain access to the system level by exploiting a flaw in the Windows Local Task Scheduler Advanced Local Call Call (ALPC) function.

Details of the vulnerability were posted on Twitter in late August and used almost immediately in an active malware distribution campaign by a criminal group known as PowerPool.

As for the other serious vulnerabilities that are being fixed but not yet used in attacks, according to Microsoft. The three are:

CVE-2018-8409 - System.IO.Pipelines Denial of Service
CVE-2018-8457 - Ευπάθεια of Scripting Engine memory
CVE-2018-8475 - An issue for remote code execution on Windows

Of these three, the first is rated as "Important," while the second and third are rated as "Critical." Out of all 62 vulnerabilities patched this month, 17 are marked as "Critical".

In addition to the flaws in its products, Microsoft has also released fixes for the big patient Adobe Flash Player.
Flash Player updates (ADV180023), are also included in the Patch Tuesday of September 2018. This month, Adobe was released a repair for a single security flaw in Flash Player, (CVE-2018-15967).

_________________________

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).