Microsoft 's November Patch Tuesday brought fixes for a total of 53 security vulnerabilities, of which at least 23 allowed remote code execution.
However, we do not have any critical updates for Windows this month, although there are four different vulnerabilities with public exploits.
Browsers received particular attention, with Internet Explorer and Microsoft Edge receiving significant security patches but no attacks reported so far.
First we have CVE-2017-11882, a significant vulnerability according to Microsoft, which could have Proof of Concept code available so users should install the update immediately.
We also encounter a scripting engine flaw in both Microsoft Edge and Internet Explorer, which could allow attackers to gain user privileges when a malicious website is loaded in either browser. The flaws are documented as CVE-2017-11836, CVE-2017-11837, CVE-2017-11838, CVE-2017-11839, CVE-2017-11871, and CVE-2017-11873.
IT professionals are advised to pay special attention to Windows updates that fix CVE-2017-11830 and CVE-2017-11847 as these are two vulnerabilities that involve security feature bypasses.
Windows 10 systems also received a bunch of cumulative updates depending on the version they are running that will fix all security vulnerabilities.
Windows 10 Fall Creators Update has already received a Patch Tuesday with successful installation of the updates.
As always, updates require a reboot and in the case of large networks, work should be saved before installation.
