Microsoft patches record 622 vulnerabilities, including two actively exploited zero-days

Published:

spot_img

Microsoft has issued a significant security update, addressing a record 622 vulnerabilities in its products, including two actively exploited zero-day vulnerabilities. This update, part of July’s Patch Tuesday, marks a dramatic increase in vulnerabilities patched compared to previous months, with 62 classified as critical. Organizations using Microsoft products should prioritize applying these patches to mitigate potential risks.

What the advisory covers

This advisory details the extensive patching effort by Microsoft, highlighting the unprecedented number of vulnerabilities addressed in a single month. The update is particularly critical due to the presence of zero-day vulnerabilities that are currently being exploited.

Affected products and versions

  • Microsoft Windows
  • Microsoft Office
  • Microsoft Exchange Server
  • Microsoft Dynamics
  • Microsoft Edge

Severity and exploitation status

Among the 622 vulnerabilities, 62 are rated as critical. Notably, three of these vulnerabilities are zero-days, with two confirmed to be actively exploited in the wild. This situation underscores the urgency for organizations to implement the patches without delay.

Available patches or fixed versions

Organizations should refer to the official Microsoft security update guide for detailed information on the specific patches available for each affected product. It is essential to ensure that all systems are updated to the latest versions to mitigate vulnerabilities.

Recommended actions

  • Immediately apply the latest patches provided by Microsoft.
  • Conduct a thorough review of all systems to identify any that may be vulnerable.
  • Implement monitoring for any unusual activity that may indicate exploitation attempts.
  • Educate staff about the importance of timely updates and the risks associated with unpatched vulnerabilities.

For further details and to access the full advisory, visit Cisco Talos.

spot_img

Related articles

Recent articles

Project CAV3RN Expands Espionage Capabilities with Google Apps Script in Israel

Project CAV3RN, a modular espionage framework targeting entities in Israel, has recently expanded its capabilities by integrating Google Apps Script into its command and...

Red Hat releases important security update for gstreamer1-plugins-bad-free in RHEL 8.6

Red Hat has announced an important security update for the gstreamer1-plugins-bad-free package, applicable to Red Hat Enterprise Linux (RHEL) 8.6 Advanced Mission Critical Update...

Flaw in OpenAI, Anthropic, and Google APIs Allows Weaker AI Models to Decode Stronger Models’ Reasoning

A newly disclosed flaw in the APIs of OpenAI, Anthropic, and Google has raised significant security concerns, allowing researchers to recover internal reasoning and...

Cyberattacks Target North Carolina Ports and Ryde, Exposing Millions of Records

In a week marked by significant cyber incidents, the cybersecurity landscape has seen notable attacks targeting critical infrastructure and major companies. The latest Threat...