National Cyber Warfare Foundation (NCWF)

Microsoft Patch Tuesday for January 2024 fixed 2 critical flaws


0 user ratings
2024-01-09 22:50:09
milo
Blue Team (CND)

 - archive -- 
Microsoft Patch Tuesday security updates for January 2024 addressed a total of 49 flaws, including two critical vulnerabilities. Microsoft Patch Tuesday security updates for January 2024 fixed 49 flaws in Microsoft Windows and Windows Components; Office and Office Components; Azure; .NET Framework and Visual Studio; SQL Server; Windows Hyper-V; and Internet Explorer. The IT giant […

Microsoft Patch Tuesday security updates for January 2024 addressed a total of 49 flaws, including two critical vulnerabilities.





Microsoft Patch Tuesday security updates for January 2024 fixed 49 flaws in Microsoft Windows and Windows Components; Office and Office Components; Azure; .NET Framework and Visual Studio; SQL Server; Windows Hyper-V; and Internet Explorer. The IT giant also addressed multiple Chromium bugs, bringing the total number of fixed issues to 53.





“None of the CVEs released today are listed as publicly known or under active attack at the time of release.” reported the post published by the Zero Day Initiative.





Two of the addressed vulnerabilities are rated Critical, the remaining 47 issues are rated Important in severity.





The critical vulnerabilities are:






  • CVE-2024-20700 – Windows Hyper-V Remote Code Execution Vulnerability. Successful exploitation of this vulnerability requires that an attacker will need to first gain access to the restricted network before running an attack.




  • CVE-2024-20674 – Windows Kerberos Security Feature Bypass Vulnerability. An unauthenticated attacker could exploit this vulnerability by establishing a machine-in-the-middle (MITM) attack or other local network spoofing technique, then sending a malicious Kerberos message to the client victim machine to spoof itself as the Kerberos authentication server. This vulnerability can be exploited by an attacker only after gaining access to the restricted network prior to launching an attack.





The complete list of vulnerabilities addressed by Microsoft is available here.





Follow me on Twitter: @securityaffairs and Facebook and Mastodon





Pierluigi Paganini





(SecurityAffairs – hacking, Microsoft Patch Tuesday)







Source: SecurityAffairs
Source Link: https://securityaffairs.com/157190/security/microsoft-patch-tuesday-january-2024.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2025 - National Cyber Warfare Foundation - All rights reserved worldwide.