Microsoft fixes 97 vulnerabilities during Patch Tuesday, including one zero-day
Microsoft patched 97 vulnerabilities during the Patch Tuesday monthly update cycle. One of them was a zero day. During the round of patches, seven bugs were classified as ‘critical’ because they enabled remote code execution.
The updates are KB5025239 for Windows 11 Build 22621.1555 and KB5025221 for Windows 10 versions 19042.2846, 19044.2846 and 19045.2846. During the patch round, Microsoft fixed 97 vulnerabilities. One of them is a zero day. That is CVE-2023-28252, a privilege escalation in the log file system. The bug gets a CVSS score of 7.8. According to Microsoft, the vulnerability was not exploited in practice, but was previously discovered by Kaspersky, which says that the bug was exploited in Nokoya ransomware attacks.
In addition to the zero-day, 45 remote code executions and twenty other privilege escalations were discovered in the update cycle. Seven of the bugs have been classified as ‘critical’. This means they can be easily exploited without the need for victim intervention. The label ‘important’ is applied to no fewer than ninety vulnerabilities.