TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Microsoft Patches Six Zero-Day Security Holes

243 pointsby parsecsalmost 4 years ago

7 comments

dlsaalmost 4 years ago
So these vulns weren&#x27;t needed any more by some 3 letter agency? Or were they being used by someone a 3 letter agency didn&#x27;t like? Or were about to be?<p>Security warfare is fascinating to watch from the mud huts.
评论 #27444437 未加载
评论 #27443844 未加载
userbinatoralmost 4 years ago
<i>–CVE-2021-33742, a remote code execution bug in a Windows HTML component.</i><p>The only one that stands out as being a real concern, but who&#x27;s willing to bet it requires JS to exploit (or even if not, the attackers prefer to obfuscate it using JS)? Turning off JS by default in IE is probably the single most effective way of preventing these attacks. Even if you don&#x27;t use IE, it&#x27;ll greatly reduce the attack surface. I&#x27;ve browsed the shadier parts of the Internet for literally decades this way.
评论 #27443884 未加载
评论 #27444732 未加载
评论 #27448336 未加载
评论 #27443286 未加载
评论 #27443851 未加载
评论 #27443353 未加载
ck2almost 4 years ago
So wait, Microsoft is still making patches for Windows7, they just aren&#x27;t supplied via the windows-update ?<p><a href="https:&#x2F;&#x2F;www.catalog.update.microsoft.com&#x2F;Search.aspx?q=KB5003667" rel="nofollow">https:&#x2F;&#x2F;www.catalog.update.microsoft.com&#x2F;Search.aspx?q=KB500...</a><p>Is there a third party program that finds&#x2F;installs the windows 7 updates?
评论 #27444259 未加载
评论 #27445038 未加载
nodesocketalmost 4 years ago
Are these on the same level as Stuxnet? For an amazing technical deep dive into each 0-day Stuxnet vulnerability watch this talk with Bruce Dang from Microsoft[1]. I really enjoy his natural speaking style (it&#x27;s like talking about Stuxnet over beers with him).<p>[1] <a href="https:&#x2F;&#x2F;youtu.be&#x2F;rOwMW6agpTI?t=409" rel="nofollow">https:&#x2F;&#x2F;youtu.be&#x2F;rOwMW6agpTI?t=409</a>
joenathanonealmost 4 years ago
Do the Microsoft links not work for anyone else too? I get a &quot;Something went wrong&quot; error on all the links. Would like to read more about specific vulns.
评论 #27442655 未加载
waynesonfirealmost 4 years ago
are these the six zero days that were used to get those bit coins back?
评论 #27442645 未加载
评论 #27443071 未加载
afrcncalmost 4 years ago
Wow... patch tuesday analysis from a reporter who doesn&#x27;t know how virus total works <a href="https:&#x2F;&#x2F;twitter.com&#x2F;silascutler&#x2F;status&#x2F;1383085248381128715" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;silascutler&#x2F;status&#x2F;1383085248381128715</a>
评论 #27445260 未加载
评论 #27442988 未加载