2024-04-10
Patch Tuesday: Microsoft
On Tuesday, April 9, Microsoft released its monthly security update, which addresses nearly 150 CVEs. Three of the vulnerabilities are rated critical; all three are remote code execution flaws affecting Microsoft Defender for IoT. A fourth flaw a proxy driver spoofing vulnerability was previously disclosed and has been actively exploited.
Editor's Note
This patch Tuesday was a bit odd. Many of the vulnerabilities are caused by a small number of components, and the only product affected by critical vulnerabilities is Defender for IoT. The already exploited vulnerability is a driver certificate that was abused and is being revoked with this update.
Johannes Ullrich
The glass half full of this record number of flaws found in Windows would be that Microsoft's recognition of lack of attention to security that was exposed last year has resulted in more investment in testing/finding/removing vulnerabilities. However, it will take several months of decreasing patch count, and faster releases of patches, to show that the glass is not still half empty. Also see the Adobe Patch item today.
John Pescatore
There are around 40 RCE patches for MS OLE driver for SQL Server and seven RCE fixes for their DNS server. As much as OLE is a fact of life, you want those updates deployed. Even though MS states you effectively need a perfect storm of events to exploit the DNS flaws, that service is critical enough to warrant deploying the patches rather than skipping or postponing until something happens.
Lee Neely
Read more in
SANS ISC: April 2024 Microsoft Patch Tuesday Summary
Krebs on Security: April's Patch Tuesday Brings Record Number of Fixes
The Register: Microsoft squashes SmartScreen security bypass bug exploited in the wild
SC Magazine: Microsoft fixes a record 147 bugs in April release of Patch Tuesday
Bleeping Computer: Microsoft fixes two Windows zero-days exploited in malware attacks
Dark Reading: Microsoft Patch Tuesday Tsunami: No Zero-Days, but an Asterisk
Microsoft: April 2024 Security Updates