Microsoft released patches for 67 CVEs in its latest December 2021 Patch Tuesday update. Out of 67 vulnerabilities, 60 were deemed important, and seven were critical. Six zero-day vulnerabilities have also been fixed, which were being exploited in the wild.
The December 2021 Patch Tuesday update resolved vulnerabilities affecting Microsoft Office, Microsoft PowerShell, the Chromium-based Edge browser, the Windows Kernel, Print Spooler, and Remote Desktop Client.
For #PatchTuesday, @briankrebs shares a round-up of security updates from Microsoft, Adobe, & Google, incl. Microsoft’s fix for patch bypass CVE-2021-43883, an elevation of privilege vuln in Windows Installer.
Our Staff Research Engineer @satnam w/ more: https://t.co/L6OtRiTatk
— Tenable (@TenableSecurity) December 15, 2021
Tenable has identified three vulnerabilities as critical:
Brian Krebs, on krebsonsecurity.com, shared, “The Microsoft patches include six previously disclosed security flaws, and one that is already being actively exploited. This month’s Patch Tuesday is overshadowed by the “Log4Shell” 0-day exploit in a popular Java library that web server administrators are now racing to find and patch amid widespread exploitation of the flaw.”
The remote code execution (RCE) vulnerability “Log4Shell” in the Apache Log4j library allows attackers to execute arbitrary code and take full control of the vulnerable devices. It is a popular Java logging library leveraged by numerous organizations worldwide to enable logging in a wide set of popular applications. It is being viewed as one of the most devastating flaw and we have just begin to explore the tip of the iceberg. Read the full story here.
The post Microsoft Fixes 6 Zero-day Flaws in December 2021 Patch Tuesday Update appeared first on CISO MAG | Cyber Security Magazine.
Click to Open Code Editor