Two Active Zero-Days Exploits and 4 Critical RDP Flaws


79 Vulnerabilities

Microsoft released security updates for September that addresses 79 security vulnerabilities, out of the 17 are critical, 61 rated as important and one classified as Moderate.

The update covers two active Elevation of Privilege Zero-Days Vulnerabilities CVE-2019-1215 & CVE-2019-1214.

CVE-2019-1214 – Vulnerability exists in Windows Common Log File System, successful exploitation of the vulnerability allows an attacker to run processes in an elevated context.

CVE-2019-1215 – Vulnerability exists in ws2ifsl.sys (Winsock), successful exploitation allows an attacker to execute code with elevated privileges.

Read more…