Microsoft finally released yesterday the monthly security updates as part of Patch Tuesday.
This month, the company from Redmond fixed 64 vulnerabilities, 17 of which were critical. Among them were also two zero days for the Windows operating system.
First 0DAY
The first zero day was published by Google last week and according to the company could be exploited in 32-bit Windows systems.
Today, Microsoft released a security update not only for Windows 7, but also for Windows Server 2008 systems, which are also affected by the CVE-2019-0808.
Second 0DAY
The second zero-day was discovered by Kaspersky researchers and is listed as CVE-2019-0797. Just like the first, it is an elevation of privilege (EoP) bug that could allow attackers to run code with administrator privileges.
This zero day affects all Windows versions.
Other fixes
In addition to the two zero days, Microsoft fixed (again) three major vulnerabilities in the Windows DHCP client that allowed remote attackers to take control of vulnerable systems (CVE-2019-0697, CVE-2019-0698, and CVE-2019-0726).
So according to the above, it is considered necessary to upgrade your systems immediately (although we usually say not to do it immediately).
