Microsoft's April 2023 Patch Tuesday Addresses 97 Flaws and Ransomware Exploits.

Microsoft has released security updates to fix 97 flaws impacting its software, including a vulnerability actively exploited in ransomware attacks. The flaw, CVE-2023-28252, is a privilege escalation bug in the Windows Common Log File System Driver. At least 32 vulnerabilities have been identified in CLFS since 2018. The updates also include fixes for critical remote code execution flaws impacting DHCP Server Service, Layer 2 Tunneling Protocol, Raw Image Extension, Windows Point-to-Point Tunneling Protocol, Windows Pragmatic General Multicast, and Microsoft Message Queuing. Other vendors have also released security updates to rectify several vulnerabilities.
- Urgent: Microsoft Issues Patches for 97 Flaws, Including Active Ransomware Exploit The Hacker News
- Windows zero-day vulnerability exploited in ransomware attacks BleepingComputer
- Microsoft (& Apple) Patch Tuesday, April 2023 Edition – Krebs on Security Krebs on Security
- April Patch Tuesday: Ransomware gangs already exploiting this Windows bug The Register
- Microsoft April 2023 Patch Tuesday fixes 1 zero-day, 97 flaws BleepingComputer
Reading Insights
0
18
4 min
vs 5 min read
89%
843 → 92 words
Want the full story? Read the original article
Read on The Hacker News