August Patch Tuesday proves busy with six zero-days to fix | Computer Weekly
Summary
Also in the crosshairs of malicious actors this month are no fewer than nine flaws, two of them third-party issues coming from Red Hat, that carry critical severity ratings. None of these critical flaws make the list of zero-days, but coming amid one of the larger Patch Tuesday updates so far this year, comprising over 100 fixes once third-party issues are accounted for, they will doubtless occupy a lot of time over the next few days. “Microsoft has evidence of in-the-wild exploitation … or public disclosure for 10 of the vulnerabilities published today, which is significantly more than usual,” said Rapid7 lead software engineer, Adam Barnett. Running the rule over the list of zero-days, Goettl said CVE-2024-38189 was likely to be the most impactful as it allows an attacker to socially engineer their way into executing arbitrary code on their victim’s system. The flaws that have been made public, but are not yet seen as exploited in the wild, are as follows: Reviewing these four issues, Scott Caveza, staff research engineer at Tenable, said CVE-2024-38202 and CVE-2024-21302 warranted particular attention.