2 Separate Vulnerabilities Affecting Microsoft Software Have Been Detected

Two zero-day vulnerabilities have been detected affecting applications such as Microsoft Edge, Skype and Teams. Microsoft has released the necessary updates.

US-based technology giant Microsoft has two open source libraries named “webp” and “libvpx”. zero day vulnerability announced that it detected and closed these vulnerabilities. According to the statement, the vulnerabilities affected consumers using the company’s most popular services such as Skype, Teams and Edge. Microsoft stated that zero-day vulnerabilities are also known to hackers, and some users have been subjected to cyber attacks due to these vulnerabilities. may have been exposed told.

According to cyber security experts working at Google and Citizen Lab, two zero-day vulnerabilities detected in September through spyware used for individuals. Meanwhile; Let’s say that security vulnerabilities affect not only Microsoft but also all other technology companies. Because webp and libvpx are the libraries that we all use and come across, even if we are not even aware of it. The simplest example; to your computer, phone or tablet via the Google search engine. If you download imagesthe download extension will most likely be webp.

It is unknown how many people are affected

Not just Microsoft; How many users have been affected so far by security vulnerabilities that also affect companies such as Apple, Google and Firefox? Unknown. However, it is likely that many more users are affected by these vulnerabilities than expected. Because, in a study conducted last month, Citizen Lab found that if the spyware created for this vulnerability infects the iPhone, the phone can be directly hacked had emerged.

RELATED NEWS

Chrome, Opera, Firefox… Critical Vulnerability Detected in All Browsers, Update Whatever You Are Using Immediately!

Microsoft published a brief statement on the subject on its official website. In this statement, there is something other than what we have conveyed to you. no details available. Meanwhile; A more detailed explanation is that there are technology news sites that reach Microsoft, but Microsoft Didn’t give details Let’s also point out.

Source :
https://msrc.microsoft.com/blog/2023/10/microsofts-response-to-open-source-vulnerabilities-cve-2023-4863-and-cve-2023-5217/


source site-34