August Patch Tuesday : Microsoft fixed two security vulnerabilities that affect all supported versions of Windows.
The company said Tuesday that an attacker could remotely exploit a remote code execution vulnerability rated "critical" using the way Windows search handles objects in memory, allowing complete control of the affected computer.
An attacker could then install whatever programs they want, read, change or delete data, create new accounts with full user rights. According to the company, all an attacker has to do to gain access to all of the above is send a specially crafted message to the Windows search service.
Microsoft added that an attacker could remotely trigger the flaw via an SMB on a network. The vulnerability was discovered by researchers at Trend Micro.
Each of the above vulnerabilities can affect any supported version of Windows, from Windows 7 and all versions of Windows 10 as well as Windows Server systems.
Although technical details or PoCs have not been made public for obvious reasons, Microsoft warns that there is a possibility of future attacks.
Another “critical” remote code execution flaw in the classic JET database engine could allow an attacker to take complete control of a computer.
Microsoft released updates for another 46 vulnerabilities as part of its regularly scheduled Patch Tuesday updates. More than half of the vulnerabilities being fixed are rated "critical.".
The August updates are available via Windows Update. Of course, it is recommended that you update your systems immediately, or finally make the decision to install Linux.
But before you do that, read the following article:
What is the best Linux distribution for platform beginners?
