Today is Microsoft's January 2024 Patch Tuesday, which includes security updates for a total of 49 flaws and 12 remote code execution vulnerabilities.
The total count of 49 flaws does not include 4 Microsoft Edge flaws fixed on January 5th. To learn more about the non-security updates released today, you can review our dedicated articles on the new Windows 11 KB5034123 cumulative update.
While there were no actively exploited or publicly disclosed vulnerabilities this month, some flaws are more interesting than others.
Microsoft fixes an Office Remote Code Execution Vulnerability tracked as CVE-2024-20677 that allows threat actors to create maliciously crafted Office documents with embedded FBX 3D model files to perform remote code execution.
A critical Windows Kerberos bug tracked as CVE-2024-20674 was also fixed today, allowing an attacker to bypass the authentication feature.
Below is the complete list of resolved vulnerabilities in the January 2023 Patch Tuesday updates.
To access the full description of each vulnerability and the systems it affects, you can view the full report here.
Windows 10 KB5033372 update released with Copilot for everyone, 20 changes.
Windows 10 KB5032189 update released with 11 improvements.
Windows 11 KB5034123 update released with security and Wi-Fi fixes.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Tue, 09 Jan 2024 19:10:25 +0000