Microsoft Patch Tuesday Resolves RCE Flaws in MSHTML

Share post:

Microsoft has issued over 60 security patches to address identified vulnerabilities, including a remote code execution (RCE) flaw in MSHTML that is used in a limited number of attacks on Windows systems and other serious bugs.

According to the Zero Day Initiative, 11 vulnerabilities were filed for a total of 86 CVEs, including 66 CVEs (three critical, one moderate, and the rest classified as important) and 20 CVEs patched earlier by Microsoft Edge (Chromium) in early September.

Some other known vulnerabilities patched by Microsoft include CVE-2021-38647, a critical bug that affects the Open Management Infrastructure(OMI) and allows attackers to conduct RCE attacks without authentication by sending malicious messages via HTTP to port 5986.

For more information, read the original story in ZDNet.


Related articles

Cyber Security Today, Week in Review for week ending Friday, June 21, 2024

Welcome to Cyber Security Today. This is the Week in Review edition for the week ending Friday June...

Cyber Security Today, June 21, 2024 – US to ban Kaspersky for businesses, consumers

U.S. to ban the sale of Kaspersky products to consumers and businesses. Welcome to Cyber Security Today. It's Friday...

Biden administration to ban US sales of Kaspersky software over ties to Russia

The Biden administration is set to announce a ban on the sale of Kaspersky Lab's antivirus software in...

Security bug may allow anyone to spoof Microsoft employee emails

A security researcher claims to have discovered a bug that enables anyone to impersonate Microsoft corporate email accounts,...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways