Microsoft Tackles Record 974 CVEs in September Patch Tuesday Release
Microsoft has released its September Patch Tuesday update, addressing a record 974 CVEs. Two of the vulnerabilities were already being exploited in attacks and have been added to the CISA's Known Exploited Vulnerabilities catalog.
The two zero-day exploits affect Windows and allow local attackers to elevate privileges. The first vulnerability is in Windows Advanced Local Procedure Call (ALPC) and affects a range of older Windows releases, including Windows 10 and Windows Server 2012 through Windows Server 2022. The second exploit affects the Windows Update Stack and allows a low-privilege attacker to gain SYSTEM privileges.
Microsoft has also released updates for Office, SQL Server, Exchange Server, SharePoint Server, Azure, and developer tools. A total of 22 Critical Office-related vulnerabilities have been addressed, including 12 that can be triggered by previewing malicious content in the Preview Pane or Reading Pane without requiring the user to open the file.
The update is considered a high priority for patching due to the confirmed exploitation of the two zero-day flaws. Microsoft has urged customers to apply the updates quickly to prevent further attacks.