Close Menu
  • Home
  • Learn
  • Web Hosting
  • Website Optimization
  • Elementor
  • Tech Jobs
  • Consultations NEW
  • More
    • About
    • Contact
    • Artificial Intelligence
    • CDN
    • Deals & Discounts
    • eCommerce
    • Movies & TV Shows
    • MyListing
    • Small Business
    • Themes & Templates
    • Tools
      • Internet Speedtest
      • VPN
    • Voxel
    • VPN
    • Web Hosting Services
    • Web Security
    • WooCommerce
    • WordPress
Tags
Analytics Archive auctions wordpress theme Backups Business business directory ChatGPT city guide classified Code Editors cPanel Crocoblock Deals directory Discord Discounts dokan ecommerce education wordpress theme Featured FTP Generative AI Google Cloud Google DeepMind grocery multivendor learning management system LiteSpeed Cache lms marketplace Matomo multi-vendor Opera PHP Plugin Update responisve shopify theme Sale SEO shop SSH Trending Updates Web Hosting woocommerce wordpress World Backup Day
Facebook X (Twitter) YouTube
Binary Blackboard
  • Home
  • Learn
  • Web Hosting
    LiteSpeed Cache vs WP Rocket

    LiteSpeed Cache vs WP Rocket

    August 3, 2023
    Storage racks aligned in a computer server room.

    Shared Web Hosting: Is It the Right Choice for Your Website?

    June 10, 2023
    Memorial day seal with the word deal next to it

    Memorial Day Weekend Deals

    May 25, 2023
    Woman holding a laptop as she works on web hosting servers

    Crucial Things to Know When Choosing Web Hosting Services

    March 27, 2023
    This is the A2 Hosting logo. It says “A2 Hosting Our Speed Your Success.”

    Switching to cPanel’s Jupiter Theme

    March 27, 2023
  • Website Optimization
    Logo for Elementor

    Automatically Clear Elementor Cache and Regenerate CSS

    July 25, 2023
    Screenshot of a macOS shortcut

    Website Speedtest macOS Shortcuts

    June 24, 2023
    New method accelerates data retrieval in huge databases

    New method accelerates data retrieval in huge databases

    March 15, 2023
    LiteSpeed Cache plugin settings dashboard

    LiteSpeed Cache Settings for Voxel

    March 9, 2023
    Logo for Redis Cache

    Are You Using Redis Cache on Your Website?

    March 8, 2023
  • Elementor
    Logo for Elementor

    Automatically Clear Elementor Cache and Regenerate CSS

    July 25, 2023
    Elementor helpful tips

    Unlock the Full Potential of Elementor with These 10 Advanced Tips

    May 20, 2023
    Logo for Elementor

    Master the Art of Web Design with Elementor Pro

    May 20, 2023
    Elementor CSS Print Method Settings

    What Is CSS Print Method in the Elementor Settings? Which Should I Choose?

    May 18, 2023
    Widgets for the Elementor page builder

    Remove Unused Elementor Widgets

    January 15, 2023
  • Tech Jobs
  • Consultations NEW
  • More
    • About
    • Contact
    • Artificial Intelligence
    • CDN
    • Deals & Discounts
    • eCommerce
    • Movies & TV Shows
    • MyListing
    • Small Business
    • Themes & Templates
    • Tools
      • Internet Speedtest
      • VPN
    • Voxel
    • VPN
    • Web Hosting Services
    • Web Security
    • WooCommerce
    • WordPress
Binary Blackboard
Home»Web Security»UPDATE NOW! Microsoft and Adobe Patch Tuesday: Fixes for Actively Exploited Zero-days
Web Security

UPDATE NOW! Microsoft and Adobe Patch Tuesday: Fixes for Actively Exploited Zero-days

March 15, 20233 Mins Read20
Facebook Twitter Pinterest LinkedIn Email WhatsApp Reddit
UPDATE NOW! Microsoft and Adobe Patch Tuesday: Fixes for Actively Exploited Zero-days

Patch Tuesday

Every second Tuesday of the month, Microsoft and Adobe release their monthly updates. This regular event is known as “Patch Tuesday” and is an opportunity for vendors to fix any vulnerabilities and improve the security of their products. The latest Patch Tuesday, on April 11, 2023, saw Microsoft and Adobe fix several critical vulnerabilities, including two actively exploited zero-days.

Microsoft has fixed a total of 101 vulnerabilities for several titles, including Edge. Two of these vulnerabilities were actively exploited zero-days. On top of that, Adobe has fixed an actively exploited vulnerability in ColdFusion. These updates address publicly disclosed computer security flaws, which are listed in the Common Vulnerabilities and Exposures (CVE) database.

One of the actively exploited vulnerabilities patched in these updates is CVE-2023-23397. This is a critical Microsoft Outlook Elevation of Privilege (EoP) vulnerability that allows external attackers to send specially crafted emails to cause a connection from the victim to an external UNC location of the attacker’s control. This would leak the Net-NTLMv2 hash of the victim to the attacker who could then relay this to another service and authenticate as the victim. The mail would be triggered automatically when retrieved and processed by the Outlook client, which could result in exploitation even before the email is viewed in the Preview Pane. This vulnerability could be used to obtain a hashed token, which could then be used in a so-called “pass-the-hash” attack.

Another vulnerability is CVE-2023-24880, which is a moderate Windows SmartScreen Security Feature Bypass vulnerability. An attacker could craft a malicious file that would evade Mark of the Web (MOTW) defenses, resulting in a limited loss of integrity and availability of security features such as Protected View in Microsoft Office, which rely on MOTW tagging. This vulnerability was reportedly used in ransomware-related attacks.

The third vulnerability is classified as a priority 1 vulnerability in Adobe ColdFusion due to critical deserialization of untrusted data. This flaw can lead to arbitrary code execution, making it a high-priority target for attackers. Adobe says it is aware that CVE-2023-26360 has been exploited in the wild in very limited attacks targeting Adobe ColdFusion. Adobe recommends updating your ColdFusion versions 2021 and 2018 JDK/JRE to the latest version of the LTS releases for JDK 11. Applying the ColdFusion update without a corresponding JDK update will NOT secure the server.

It is crucial to note that keeping your systems up to date is essential in mitigating the risks associated with these vulnerabilities. It is also crucial to apply vendor-recommended security configurations and settings as outlined on the vendor’s security pages, as well as review the respective Lockdown guides.

Other vendors have synchronized their periodic updates with Microsoft. SAP has released security updates for 19 vulnerabilities, five of which were rated as critical. It is essential to keep all systems up to date with the latest patches to mitigate the risk of cyberattacks.

In conclusion, Patch Tuesday is an opportunity for vendors to improve the security of their products by fixing vulnerabilities. The latest Patch Tuesday saw Microsoft and Adobe fix several critical vulnerabilities, including two actively exploited zero-days. It is crucial to apply these patches as soon as possible to reduce the risk of cyberattacks. It is also essential to keep all systems up to date with the latest patches and to apply recommended security configurations and settings. Stay safe online by keeping your systems up to date and following best practices in cybersecurity.

Share. Facebook Twitter Pinterest LinkedIn Email WhatsApp Reddit

Related Posts

Malwarebytes save 83% 6 apps free

Malwarebytes Bundle Includes 6 Free Apps – Save $390

Memorial day seal with the word deal next to it

Memorial Day Weekend Deals

Cybersecurity

Securing Your Business Internet Network: Best Practices for Enhanced Cybersecurity

Leave A Reply Cancel Reply

You must be logged in to post a comment.

Affiliate Envato Wordpress theme banner adEnvato Wordpress theme banner ad
Menu
  • About
  • Contact
  • Developer Tools
  • Deals & Discounts
  • Sitemap
  • Privacy Policy
  • Terms of Service
Tags
Analytics Archive auctions wordpress theme Backups Business business directory ChatGPT city guide classified Code Editors cPanel Crocoblock Deals directory Discord Discounts dokan ecommerce education wordpress theme Featured FTP Generative AI Google Cloud Google DeepMind grocery multivendor learning management system LiteSpeed Cache lms marketplace Matomo multi-vendor Opera PHP Plugin Update responisve shopify theme Sale SEO shop SSH Trending Updates Web Hosting woocommerce wordpress World Backup Day
Facebook X (Twitter) YouTube
  • Privacy Policy
  • Terms of Service
Copyright © 2025 - binaryBlackboard.

Type above and press Enter to search. Press Esc to cancel.