Microsoft Patch Tuesday fixes five zero-day flaws — update now

Windows 10 button
(Image credit: Wachiwit/Shutterstock)

Microsoft has fixed five "zero-day" flaws with its latest Patch Tuesday updates released today (April 13), including one that is actively being exploited "in the wild." 

That flaw under active attack is a local escalation of privilege — it gives a local user more power over the system than the user is supposed to have — and hence is classified as "Important" but not "Critical." 

To pull off this attack, an attacker would need direct access to a Windows computer, be able to trick a legitimate user into triggering the exploit or possibly use malware that was already installed on a machine. It affects all versions of Windows 10.

Nevertheless, to inoculate your machine against this flaw and other newly disclosed vulnerabilities, run Windows Update when your system notifies you that an update is ready.

It's deemed a "zero-day" flaw because it was known of and exploited before Microsoft had a chance to fix it.

The vulnerability was discovered by Boris Larin of Kaspersky, who in a blog post described its related exploit as "an escalation of privilege (EoP) exploit that is likely used together with other browser exploits to escape sandboxes or get system privileges for further access."

In other words, it's part of a multi-stage attack chaining together several system and browser flaws. Larin said the flaw is being used by a state-sponsored hacking group that other researchers have linked to the government of India.

The other four zero-day flaws were, as Microsoft oddly put it, "publicly exposed but not exploited." That seems to imply that other parties noticed the flaws but did not abuse them. 

All four of these are deemed "Important" or "Moderate," meaning there is little risk of remote code execution, i.e. successful attacks over the internet.

There were several remote-code-execution flaws fixed with this month's round of updates. The most crucial, both deemed "Critical," include two flaws in Windows Media Video Decoder. 

Both work on Windows 7, 8.1 and 10 alike. The fact that Microsoft is including fixes for Windows 7 more than a year after the end of official support indicates that these vulnerabilities are pretty severe.

As Microsoft explains, "an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) that contains a specially crafted file that is designed to exploit the vulnerability."

"However, an attacker would have no way to force the user to visit the website," Microsoft adds. "Instead, an attacker would have to convince the user to click a link, typically by way of an enticement in an email or Instant Messenger message, and then convince the user to open the specially crafted file."

These remote-code-execution flaws are not "zero-day" ones in that Microsoft fixed them before bad guys could start using them. However, now that the secret is out, expect malicious websites to start abusing them in a matter of days.

"Patch Tuesday" is the unofficial name given to the second Tuesday of any given month, when Microsoft, Adobe and other companies release scheduled fixes for security flaws.

Paul Wagenseil

Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.

Read more
How to disable the Windows key
Microsoft patches over 160 security flaws including 3 active zero days — update your PC right now
Windows
240 million Windows 10 users are vulnerable to six different hacker exploits — protect yourself now
iPhone 16 Pro shown held in hand
Apple just patched its first zero-day flaw of the year — update your iPhone and Mac right now
Google Pixel 9 held in the hand.
Google just fixed a zero-day kernel flaw used by hackers and 47 other vulnerabilities — update your Android phone right now
Apple iPhone 16 Plus Review.
Apple just released an emergency security update for a flaw used in an ‘extremely sophisticated attack’ — update your devices right now
Android 12
Google March Android Security Update fixes two high severity vulnerabilities — update now
Latest in Online Security
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
Latest in News
Diego Luna as Cassian Andor in "Andor" season 2 trailer
New ‘Andor’ season 2 trailer teases more explosive action and a darker edge to the hit ‘Star Wars’ show
ChatGPT on iPhone
ChatGPT was down — updates on quick outage
Emma D'Arcy in House of the Dragon season 2
‘House of the Dragon’ season 3 has officially begun filming — what it could mean for the potential release window
AirPods Max in various colors
AirPods Max is getting a big update with lossless audio and ultra-low latency — here's how it works
A mosquito resting on a plant
Experts predict a spring surge in these 9 pest populations — here's what's forecast for your area
Apple Watch SE (2022) shown on wrist
Apple Watch SE 3 reportedly in ’serious jeopardy’ — here’s why