Microsoft Patches 79 Flaws Including Actively Exploited Windows Bug

Microsoft's May 2019 Patch Tuesday addresses 79 vulnerabilities, 19 of which are critical, including one actively exploited bug and a Skype eavesdropping flaw.

Microsoft releases its May 2019 Patch Tuesday updates, delivering fixes for 79 vulnerabilities that include 19 classified as Critical. This massive batch of security updates addresses a mix of publicly disclosed flaws and actively exploited bugs, prompting the company to urge all Windows users to install the patches immediately to mitigate potential security risks.

A standout fix in this release targets the Windows Error Reporting Elevation of Privilege Vulnerability, tracked as CVE-2019-0863, which researchers discover is actively exploited in the wild. This flaw allows an attacker who gains initial unprivileged access to execute arbitrary code in kernel mode, install programs, and create new administrator accounts. Additionally, Microsoft patches a publicly disclosed Skype for Android vulnerability that enables attackers to eavesdrop on user conversations without their knowledge.

Microsoft also issues a critical Remote Desktop Services fix for older operating systems such as Windows XP, Windows 7, and Windows Server 2008. This particular vulnerability poses a severe risk as it allows wormable malware to spread automatically between exposed computers, making it a high-priority update for organizations still running legacy systems.

Read More at the original source →