Can your Windows computer be compromised if you click on a malicious link or simply visit a website?
Yes. And as everything shows, the chances increase dramatically if you do not immediately upgrade your Windows systems (if you have not already done so).
Microsoft is patching 67 vulnerabilities
As part of Patch Tuesday, Microsoft released multiple security updates aimed at fixing critical vulnerabilities found in the Windows operating system as well as other company products. Vulnerable software includes Internet Explorer and Edge browsers, the Visual Studio application development environment , the Microsoft Office suite (Office Services & Web Apps), and the Malware Protection Engine .
In total, the company patched 67 vulnerabilities, 24 of which were rated critical. Five of them could allow an attacker to hack your computer simply by visiting a specially crafted website.
The specific vulnerabilities were identified in the Windows Graphics Component and affect all versions of Windows operating systems released to date, including Windows 10 /8.1 / RT 8.1 / 7, and Windows Server 2008 / 2012 / 2016. The vulnerabilities were discovered by security researcher, Hossein Lotfi, and are due to incorrect handling of embedded fonts by the Windows font library.
“An attacker could exploit these vulnerabilities by tricking an unsuspecting user into opening a malicious file or a specially crafted website containing the malicious font, which if opened in a browser, could hand over control of the affected system to the attacker,” the company says.
Windows Microsoft Graphics is affected by another DoS vulnerability that could lead to a system becoming unresponsive, and is due to incorrect handling of objects in Windows memory.
Microsoft also disclosed the details of another critical remote access vulnerability (CVE-2018-1004), which exists in the Windows VBScript Engine and affects all versions of Windows.
"In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit the vulnerability through Internet Explorer, and then convince a user to view the website," Microsoft explains.
"An attacker could also embed an ActiveX control marked 'safe for initialization' in an application or Microsoft Office document that hosts the IE rendering engine.".
In addition, Microsoft also patched multiple remote code execution vulnerabilities in Microsoft Office and Microsoft Excel, which could allow attackers to take control of systems.
The security updates also include updates for six security vulnerabilities in Adobe Flash Player, three of which have been rated as critical.
Users are advised to upgrade
Users are advised to apply security updates as soon as possible to secure their systems from malicious actions and attacks.
To install security updates, go to Settings → Update & Security → Windows Update → Check for updates to ensure your system is up to date and proceed with the necessary upgrades if required.


