Microsoft rolled out a total of 12 security updates this Patch Tuesday, 6 of which are rated as critical and another six of them flagged with an “important” severity rating.
The first and the most important update that IT admins should prioritize is MS16-144, which is known as Cumulative Security Update for Internet Explorer (3204059) and patching remote code execution flaws in Microsoft’s browser.
As it’s the case with RCE flaws, an attacker who exploits the flaw could get the same rights as the current user, which means that compromising an administrator account could provide full access to the computer and the locally-stored data.
Microsoft Office security patches
Then, there’s MS16-145, which is a Cumulative Security Update for Microsoft Edge (3204062) and fixing RCE flaws as well.
Intelligence View
⚡ tsecurity.de Intelligence
Microsoft Releases Critical Windows, Edge Browser Security Updates
Microsoft rolled out a total of 12 security updates this Patch Tuesday, 6 of which are rated as critical and another six of them flagged with an “important” sev…
Cyber Threat Intelligence & Forensik
Bedrohungsgraph · ATT&CK-Mapping · Exploit-Belege
CTI Threat Relationship Graph
Akteure · Techniken · Beziehungen
CVE / Incident Threat Actor Software MITRE ATT&CK CWE Weakness IoC
MITRE ATT&CK Matrix Navigator
Enterprise-Matrix · nur belegte Techniken
T1190TA0001 · Initial Access
Exploit Public-Facing Application
Mitigation: M1042 Network Segmentation & WAF Rule Enforcement
Quelle: Kontext-Klassifikation des Artikeltextes
Reconnaissance
–
Resource Development
–
Initial Access
Execution
–
Persistence
–
Privilege Escalation
–
Defense Evasion
–
Credential Access
–
Discovery
–
Lateral Movement
–
Collection
–
Command and Control
–
Exfiltration
–
Impact
–