Patch Tuesday For its September Patch Tuesday, Microsoft churned out fixes for 66 vulnerabilities, alongside 20 Chromium bugs in Microsoft Edge.
Affected products include: Azure, Edge (Android, Chromium, and iOS), Office, SharePoint Server, Windows, Windows DNS, and the Windows Subsystem for Linux.
Of these CVEs, three are rated critical, one is rated moderate, and the remainder are considered important.
One of the publicly disclosed CVEs, dating back to September 7, resolves a critical zero-day vulnerability in MSHTML, also known as Microsoft’s legacy Trident rendering engine (CVE-2021-40444). The flaw allows an attacker to create a malicious ActiveX control within a Microsoft Office document that hosts the…
Source link