Patch Tuesday, Microsoft’s monthly report of security updates, brought 90 CVEs, including some vulnerabilities that were being actively exploited.
Some vulnerabilities originated in Chromium, meaning both Microsoft Edge and Google Chrome may have been affected. Here are the most critical flaws and patches disclosed by Microsoft on Aug. 13.
Threat actors had already taken advantage of six zero-day exploits in particular:
SEE: Organizations may want to assess how their privacy and data storage policies intersect with Microsoft’s Copilot AI.
Other notable items in this month’s Patch Tuesday were those rated as critical according to the National Vulnerability Database’s Common Vulnerability Scoring System from NIST. These were:
Another vulnerability, CVE-2024-38202, is remarkable because Microsoft has not yet released a patch for it. To mitigate this elevation of privilege vulnerability in Windows Update, Redmond recommends auditing user access to objects, operations, and files.
The complete steps for protecting against this vulnerability can be found in the recommended actions section of the vulnerability’s listing.
Business users around the world should use the most up-to-date versions of Edge as well as Google Chrome, since some of the vulnerabilities originate in the Chromium Open Source Software used in both browsers.
Relevant Chrome and Chromium vulnerabilities are as follows:
Attackers could have potentially used these vulnerabilities to perform arbitrary code execution before they were patched.
Most exploits mentioned in the patch report are covered by the August security updates, so the only action administrators need to take in response is to keep up to date.
Similarly, the mitigation for these Chromium flaws is to update Microsoft Edge or Google Chrome to the latest versions.
In Edge, check which version is running and find updates by going to the meatball menu (…) on the right-hand side. Select “Help” and “Feedback,” then select “Microsoft Edge.”
In Chrome, select “About Google Chrome” in the menu bar or select the kebab menu (three vertical dots) on the top-right of the window. From there, select “Help,” then “About Google Chrome.”