Patch Tuesday Microsoft rang in the New Year with a relatively calm Patch Tuesday: Just 49 Windows security updates including fixes for two critical-rated bugs, plus four high-severity Chrome flaws in Microsoft Edge.
None of the January CVEs are under active exploit, according to Redmond.
Of the two critical vulnerabilities, CVE-2024-20674 received the highest CVSS rating.
It's a 9.0-rated security feature bypass bug in Windows Kerberos.
The good news is that before launching an attack, a criminal would first need to gain access to the restricted network.
The second critical-rated update fixes CVE-2024-20700, a 7.5-rated remote code execution bug in Windows Hyper-V hypervisor.
Exploiting this hole isn't easy: an attacker would need to be inside the network to exploit the issue.
Luckily, it doesn't appear that any of the CVEs have been exploited prior to the patch.
SAP issued 12 new and updated patches, including three HotNews Notes and four High Priority Notes.
Two of the NotNews Notes are new, and all three received CVSS scores of 9.1.
One of the new HotNews Notes, #3413475, addresses an escalation of privileges vulnerability in SAP Edge Integration Cell due to CVE-2023-49583 and CVE-2023-50422.
The other, #3412456, also fixes Escalation of Privileges in applications developed through SAP Business Application Studio, SAP Web IDE Full-Stack, or SAP Web IDE for SAP HANA. These applications may also be affected by CVE-2023-49583, according to Thomas Fritsch, SAP security researcher at Onapsis.
Cisco released its final update for two privilege escalation CVEs in its Identity Services Engine that were originally disclosed in September.
The bugs are tracked as CVE-2023-20193 and CVE-2023-20194 and only the latter has a patch.
Google's January Security Bulletin for Android addresses 59 CVEs, but none of these appear to have been found and exploited by criminals prior to the patches.
The most severe of the bunch exists in the Framework components.
Google says it would lead to local escalation of privilege with no additional execution privileges needed.
This Cyber News was published on go.theregister.com. Publication date: Tue, 09 Jan 2024 22:43:06 +0000