These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Of these, over 110 shortcomings have been assigned a critical severity rating. Three prominent vulnerability types, namely privilege escalation, remote code execution, and information disclosure, account for nearly 90% of the flaws patched this month. Along with Microsoft’s fixes for 25 non-Microsoft CVEs, the update brings the total number of vulnerabilities resolved to 999.
September’s record-setting security updates come after Microsoft patched 457 vulnerabilities in August, 663 in July, 220 in June, and 161 in May.
“At this scale, the challenge is not simply getting through the patch list but knowing what needs attention first,” Jack Bicer, director of vulnerability research at Action1, said. “With hundreds of updates landing at once, IT and security teams need to quickly separate the vulnerabilities that demand immediate action from those that can follow the normal deployment cycle.”
…
“I think it is safe to say that, as long as Microsoft is playing catch-up on patching vulnerabilities, numbers have lost all meaning,” Tyler Reguly, associate director of Security R&D at Fortra, said.
🔗 Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
Leave a Reply