Internet Connectz
  • Home
  • Trump Connectz
  • Latest News
  • Internet Shop
  • Cart
  • Check Out
  • Trenden Music
  • DIY Connectz
  • Environment Connectz
  • Food Connectz
  • Gaming Connectz
  • Gavin Newsom Connectz
  • Health Connectz
  • Internet Connectz
  • News Connectz
  • Politic Connectz
  • Ron Desantis Connectz
  • Sport Connectz
  • Technology Connectz
  • Travel Connectz
  • Trump Connectz
  • World News Connectz
News Connectz

Microsoft rolls out 47 patches in December update – Security

07/03/2024 internetconnectz.com No comments yet
Summarize this post with AI
ChatGPT Gemini Claude Perplexity Copilot
internet connectz

Microsoft has ended 2023 with a light “Patch Tuesday” workload: of the 47 patches, only two have a Common Vulnerabilities Scoring System (CVSS) rating greater than 9.

Microsoft rolls out 47 patches in December update

Only one of the vulnerabilities was previously disclosed, and there are no zero-days already exploited.

The first of the critical vulnerabilities, CVE-2023-36019, has a CVSS score of 9.6. 

It’s a spoofing vulnerability that affects the OAuth 2.0 implementation in Microsoft’s Power Platform connectors.

The bug is fixed by updating the per-connector URI, according to the instructions outlined here.

The second critical-rated vulnerability, CVE-2023-35618, also has a CVSS score of 9.6.
It’s a Chromium browser sandbox escape in Edge, that leads to escalation of privilege.

“In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) that contains a specially crafted file that is designed to exploit the vulnerability,” Microsoft’s advisory said.

An attacker “would have to convince the user to click a link, typically by way of an enticement in an email or Instant Messenger message, and then convince the user to open the specially crafted file.”

Because of the complex attack scenario, Microsoft only described the bug as “moderate” in spite of its CVSS score.

The previously disclosed bug is an AMD issue that was first revealed in August and carries a CVSS score of 5.5.

AMD’s advisory explained: “a register in “Zen 2” CPUs may not be written to 0 correctly. This may cause data from another process and/or thread to be stored in the YMM register, which may allow an attacker to potentially access sensitive information.”

Richard Chirgwin

Source link

Post Views: 146
  • technology connectz

Post navigation

Previous
Next

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related posts

Technology Connectz

[Dev Letter] Anti-Cheat System Improvements – NEWS

04/17/2026 internetconnectz.com No comments yet

Hello Players,This is the PUBG: BATTLEGROUNDS Anti-Cheat Team. We continuously advance our anti-cheat systems to ensure a fair competitive environment for all players. In this Dev Letter, we’d like to share updates of our recent efforts to reduce false bans, strengthen countermeasures against network abuse in console environments, and expand detection of macro mouse usage. […]

Technology Connectz

NVIDIA vs Tesla (NVDA vs TSLA): AI Infrastructure vs Robotaxi 2026

04/17/2026 internetconnectz.com No comments yet

NVIDIA and Tesla are the two most-owned AI stocks in retail portfolios, and they are running almost opposite playbooks. NVIDIA is the infrastructure monopoly: $68.1 billion in Q4 FY2026 revenue, $62 billion of it from the data center, and a Blackwell-to-Rubin roadmap that has every hyperscaler on earth signed into a multi-year order book. Tesla […]

internet connectz
Technology Connectz

Latest AI models could threaten world banking system, financial officials warn

04/17/2026 internetconnectz.com No comments yet

“The evolution of digital technology is posing immense risks from a cyber security perspective,” said Dan Katz, deputy head of the IMF and former … Source link

© Internet connecz. All rights reserved.

We use cookies to ensure you get the best experience on our website.