Microsoft addresses Office vulnerability attacked by Russian spooks in latest update | Computer Weekly

General News

Summary

Amid the ongoing Black Hat USA and DEF CON cyber jamborees, Microsoft has addressed a little over 70 vulnerabilities in its August Patch Tuesday update, including two zero-days already being exploited, more than 20 remote code execution (RCE) flaws, and six critical bugs. “A denial of service (DoS) attack involves overrunning it with an excessive volume of requests, which exhausts its available resources, such as processing power, memory, or network bandwidth. “According to the CVE details code maturity has reached proof-of-concept and it is confirmed to be exploited in the wild,” Ivanti’s Goettl told Computer Weekly in emailed comments. Also attracting attention this month are a series of six flaws in Microsoft Exchange Server, the most significant of which is CVE-2023-21709, an elevation of privilege (EoP) vulnerability. “The remaining five vulnerabilities range from a spoofing flaw and multiple remote code execution bugs, though the most severe of the bunch also require credentials for a valid account,” he added.

Classifications

industries
Entertainment
applications
Accounting and Taxes

AskAI Classifications

Labels
Cybersecurity Training Software SaaS Enterprise Software

Linked Companies

Immersive Labs
$10M to $25M
FlawCheck
$500M to $1B
LANDESK Software
$50M to $100M
Microsoft
$1B+
Tenable, Inc.
$500M to $1B
Ivanti
$500M to $1B