Microsoft Fixes 66 Vulnerabilities Across Its Products

Microsoft’s April security updates include fixes for 66 vulnerabilities in Windows components, the Edge and Internet Explorer browsers, the Office suite, the Hyper-V hypervisor, Visual Studio and even a wireless keyboard. Of the 66 flaws, 22 are… Continue reading Microsoft Fixes 66 Vulnerabilities Across Its Products

Microsoft Patches Critical Windows DNS Client Vulnerabilities

Microsoft patched three memory corruption vulnerabilities in the Windows DNS client that could be abused by a man-in-the-middle attacker to run arbitrary code. Continue reading Microsoft Patches Critical Windows DNS Client Vulnerabilities

Microsoft Addresses NTLM Bugs That Facilitate Credential Relay Attacks

Microsoft today addressed two NTLM-related vulnerabilities privately disclosed by Preempt Security. The flaws allow for credential relay attacks. Continue reading Microsoft Addresses NTLM Bugs That Facilitate Credential Relay Attacks

Rare XP Patches Fix Three Remaining Leaked NSA Exploits

Microsoft released patches on Tuesday for unsupported versions of Windows, a decision prompted by three NSA exploits that remained unaddressed from April’s ShadowBrokers leak. Continue reading Rare XP Patches Fix Three Remaining Leaked NSA Exploits

Office Zero Day Delivering FINSPY Spyware to Victims in Russia

Researchers have learned that the recently patched Office zero day was used to target victims in Russia with FINSPY spyware. Continue reading Office Zero Day Delivering FINSPY Spyware to Victims in Russia

Patch Tuesday Returns; Microsoft Quiet on Postponement

Microsoft released 18 security bulletins, eight rated critical. The company also patched publicly disclosed vulnerabilities that surfaced since last month’s postponement of Patch Tuesday. Continue reading Patch Tuesday Returns; Microsoft Quiet on Postponement

Second Try at Windows LSASS Patch Addresses Vulnerability

Microsoft on Tuesday patched a vulnerability in LSASS, the second attempt it has taken at fixing a remote denial-of-service issue in the critical Windows process. Continue reading Second Try at Windows LSASS Patch Addresses Vulnerability