Skip to content
Tech News
← Back to articles

Microsoft fixes 421 bugs and a Windows zero-day in August Patch Tuesday - update ASAP

read original more articles
Why This Matters

Microsoft's August Patch Tuesday addresses a critical security concern by fixing 421 vulnerabilities, including a zero-day flaw actively exploited in the wild. This highlights the importance for Windows users and organizations to promptly update their systems to prevent potential breaches and maintain security integrity in an increasingly threat-prone landscape.

Key Takeaways

Lance Whitney / ZDNET

Follow ZDNET: Add us as a preferred source on Google.

ZDNET's key takeaways

Microsoft's August Patch Tuesday fixes 421 vulnerabilities.

One vulnerability has already been exploited in the wild.

The update also tweaks File Explorer, Windows Hello, and other features.

Microsoft continues its onslaught against security vulnerabilities, fixing a whopping 421 bugs in August's Patch Tuesday update. But looking beyond the sheer number, Windows users should install this month's update, as it patches a zero-day flaw that's already been exploited by attackers.

Aimed at Windows 11 25H2/24H2, Windows 11 23H2, and Windows 10, the 421 vulnerabilities encompass a range of Microsoft products, including Office, Exchange, Azure, and SharePoint. But it's the Windows patches that clobber the exploited zero-day. In technical jargon, Microsoft titles this flaw a "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability." What that means isn't as important as what it could do.

Also: A developer got Word 1.1a from 1990 to run on Windows 11 - try it yourself

By exploiting this bug, an attacker could gain system privileges on a Windows 11 or 10 PC without any interaction on the user's part. The person would already need lower-level access to the PC from an initial intrusion. But from there, system privileges would give the attacker the ability to view or delete your files, compromise your security, create user accounts, install malware, and enlist your PC in a botnet.

... continue reading