Internet Connectz
  • Home
  • Trump Connectz
  • Latest News
  • Internet Shop
  • Cart
  • Check Out
  • Trenden Music
  • DIY Connectz
  • Environment Connectz
  • Food Connectz
  • Gaming Connectz
  • Gavin Newsom Connectz
  • Health Connectz
  • Internet Connectz
  • News Connectz
  • Politic Connectz
  • Ron Desantis Connectz
  • Sport Connectz
  • Technology Connectz
  • Travel Connectz
  • Trump Connectz
  • World News Connectz
News Connectz

Microsoft rolls out 47 patches in December update – Security

07/03/2024 internetconnectz.com No comments yet
Summarize this post with AI
ChatGPT Gemini Claude Perplexity Copilot
internet connectz

Microsoft has ended 2023 with a light “Patch Tuesday” workload: of the 47 patches, only two have a Common Vulnerabilities Scoring System (CVSS) rating greater than 9.

Microsoft rolls out 47 patches in December update

Only one of the vulnerabilities was previously disclosed, and there are no zero-days already exploited.

The first of the critical vulnerabilities, CVE-2023-36019, has a CVSS score of 9.6. 

It’s a spoofing vulnerability that affects the OAuth 2.0 implementation in Microsoft’s Power Platform connectors.

The bug is fixed by updating the per-connector URI, according to the instructions outlined here.

The second critical-rated vulnerability, CVE-2023-35618, also has a CVSS score of 9.6.
It’s a Chromium browser sandbox escape in Edge, that leads to escalation of privilege.

“In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) that contains a specially crafted file that is designed to exploit the vulnerability,” Microsoft’s advisory said.

An attacker “would have to convince the user to click a link, typically by way of an enticement in an email or Instant Messenger message, and then convince the user to open the specially crafted file.”

Because of the complex attack scenario, Microsoft only described the bug as “moderate” in spite of its CVSS score.

The previously disclosed bug is an AMD issue that was first revealed in August and carries a CVSS score of 5.5.

AMD’s advisory explained: “a register in “Zen 2” CPUs may not be written to 0 correctly. This may cause data from another process and/or thread to be stored in the YMM register, which may allow an attacker to potentially access sensitive information.”

Richard Chirgwin

Source link

Post Views: 144
  • technology connectz

Post navigation

Previous
Next

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related posts

Technology Connectz

Torys partners with Harvey to drive firmwide AI adoption | About

04/13/2026 internetconnectz.com No comments yet

Torys is pleased to announce a partnership with Harvey for the adoption of its AI platform designed for the legal industry. The firmwide rollout positions Torys among the first Canadian firms to deploy Harvey at scale, and marks a significant advancement in Torys’ use of AI technology to enhance client service delivery. Harvey will provide […]

internet connectz
Technology Connectz

German culture minister labeled fascist at concentration camp event – Irish Sun

04/13/2026 internetconnectz.com No comments yet

Media magnate Weimar, whose company is at the center of a pay-for-influence networking event controversy, has also imposed an anti-Palestinian … Source link

Technology Connectz

UConn Health Offers New Level of Precision in Cancer Care

04/13/2026 internetconnectz.com No comments yet

Advanced radiotherapy with unprecedented levels of safety and accuracy is now available to patients at UConn Health’s Carole and Ray Neag Comprehensive Cancer Center. Radiation therapy technologists have been using the TrueBeam Linear Accelerator, on par with leading cancer centers throughout the world, since late February. UConn Health’s radiation oncology team now has the TrueBeam […]

© Internet connecz. All rights reserved.

We use cookies to ensure you get the best experience on our website.