HomeSecurityMicrosoft: Security Patch Tuesday, for February 2019

Microsoft: Security Patch Tuesday, for February 2019

MicrosoftMicrosoft on Tuesday released a series of updates to fix at least 70 different security vulnerabilities in Windows and software. This month's patch addresses some notable threats to businesses. It also provides fixes to eliminate threats relevant to end users, including critical updates for Adobe Flash Player and Microsoft Office, as well as a zero-day bug in Internet Explorer.

About 20 of the bugs, addressed by the February updates, are vulnerabilities rated "critical," meaning Microsoft believes attackers or malware could exploit them to completely compromise systems.

Microsoft has worked to fix a bug in Internet Explorer (CVE-2019-0676), discovered by Google and used by attackers to target vulnerable systems. This bug could allow malware to check for the presence of specific files on the target's hard drive.

Another critical vulnerability, affecting both end users and businesses, is a weakness in Windows. This vulnerability is responsible for assigning Internet addresses to host computers. This bug, CVE-2019-0626, could allow an attacker to execute malicious code simply by sending a specially crafted DHCP request to the target.

At the top of the list of updates, which mainly affects enterprises, is an issue with Microsoft Exchange services (CVE-2019-0686), which could allow an attacker on the same network as the target to access other users' inboxes. Microsoft said the flaw hasn't been exploited by attackers yet, but it believes it's highly likely that it will soon.

Security experts recommend using this month's patch to address Windows bugs. It's also important to back up your data before installing Windows updates.

Microsoft also included patches to address a vulnerability in Adobe Flash Player. Microsoft and Adobe disagree on the severity of the vulnerability, according to security firm Qualys. Adobe calls it a “significant” bug, while Microsoft calls it “critical.” Regardless, Flash vulnerabilities are popular targets for attackers.

Fortunately, the most popular browser—Google Chrome—updates Flash automatically (Microsoft also bundles Flash with IE/Edge and updates it whenever Windows systems install monthly updates). By summer 2019, Google will require Chrome users to go into their settings to enable Flash every time they want to use it.

Firefox also forces users to enable Flash. There are also instructions for disabling or removing Flash from Firefox. Adobe will stop supporting Flash at the end of 2020.

Finally, Adobe also released some updates for Adobe Acrobat and Reader.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS