CYBERSECURITY

Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

Microsoft did not disclose the exact nature of the exploits but confirmed they

Microsoft released a record-breaking 974 security updates on Tuesday, marking the largest Patch Tuesday in the company's history. The updates addressed vulnerabilities across Windows, Office, SQL Server, and other products, with two of the flaws confirmed to be actively exploited in attacks before the patch was made available. The scale of this update reflects growing pressure on software vendors to respond to increasingly sophisticated cyber threats. Of the 974 flaws, 723 were found in Windows operating systems, 111 in Office and Office 2016, 62 in SQL Server, and 22 in other components. Microsoft noted that the two zero-day vulnerabilities in Windows were being used in limited, targeted attacks, prompting urgent action to protect users. How These Zero-Days Were Being Used in the Wild The two actively exploited Windows zero-days allowed attackers to elevate privileges on compromised systems, potentially giving them full control over affected machines.

Microsoft did not disclose the exact nature of the exploits but confirmed they were being used in narrow, focused campaigns rather than widespread attacks. Security researchers noted that such vulnerabilities are often chained with other flaws to bypass defenses and maintain persistence inside networks. What Does This Mean for Organizations Managing Large Fleets? For IT administrators, the sheer volume of patches presents a significant challenge in testing and deployment, especially in enterprise environments where compatibility concerns can delay updates. Microsoft urged customers to prioritize the two critical zero-day fixes immediately, while scheduling the remainder based on risk assessments. The company also highlighted improvements in its patch management tools to help streamline the process for large organizations. Frequently Asked Questions Why did Microsoft release so many patches in this single update?

The high number reflects both the discovery of numerous vulnerabilities through internal and external research, and Microsoft's commitment to addressing security issues comprehensively during its regular monthly update cycle. Are the two zero-day flaws still a threat after this patch? No, applying the updates released on Tuesday mitigates the actively exploited zero-day vulnerabilities, removing the risk they posed to unpatched systems. Should home users install these updates immediately? Yes, Microsoft recommends that all users install the latest security updates as soon as possible to protect against known threats, including the two zero-days that were being exploited.

Content written by [email protected] (The Hacker News) for tech-site.news editorial team, AI-assisted.

Comments

Leave a comment