71 Vulnerabilities, 4 Zero-days Fixed On Patch Tuesday

Share post:

In the patch Tuesday for October, Microsoft released fixes for 71 vulnerabilities, one of which was actively exploited and found in Win32k.

While the fixed zero-day bugs CVE-2021-40449, CVE-2021-41338, CVE-2021-40469, and CVE-2021-41335 are being tracked, CVE-2021-40449 with a CVSS severity of 7.8 is actively exploited.

Three other zero-day bugs include CVE-2021-41338, a bug in the Windows AppContainer Firewall with a CVSS severity of 5.5 that allows attackers to bypass security features, CVE-2021-40469, an RCE in the Windows DNS Server with a CVSS severity of 7.2, and finally CVE-2021-41335, an elevated privilege bug with a CVSS severity of 7.8 found in the Windows Kernel.

Other bugs that have been fixed are three critical bugs, CVE-2021-40486, CVE-2021-38672, and CVE-2021-40461. While the first flaw impacts Microsoft Word, the other two flaws affect Hyper-V.

However, in cases where they are exploited, they can all lead to remote code execution.

For more information, read the original story in ZDNet.

SUBSCRIBE NOW

Related articles

North Korean hacker infiltrates US security vendor, loads malware

KnowBe4, a US-based security vendor, unknowingly hired a North Korean hacker who attempted to introduce malware into the...

CrowdStrike releases an update from initial Post Incident Review: Hashtag Trending Special Edition for Thursday July 25, 2024

Security vendor CrowdStrike released an update on from their initial Post Incident Review today. The first, and most surprising...

Security vendor CrowdStrike issues an update from their initial Post Incident Review

Security vendor CrowdStrike released an update from their initial Post Incident Review (PIR) today. The company's CEO has...

CrowdStrike CEO summoned by Homeland Security committee over software disaster

CrowdStrike CEO George Kurtz has been called to testify before the U.S. House Committee on Homeland Security following...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways