Microsoft's August security update addresses more than 400 vulnerabilities across Windows and Microsoft 365, including one flaw that is already being used in real-world attacks.
- What it is: This month's update covers 42 critical vulnerabilities, most of which would let an attacker run code remotely on an unpatched system.
- Actively exploited: A flaw in the Windows networking driver (Winsock) is already being exploited, letting attackers gain system-level access on affected machines.
- Also patched: A critical flaw in the Microsoft 365 Admin Center that could let an unauthenticated attacker escalate privileges, plus fixes for Exchange Server, Teams and SharePoint.
- Who is affected: Any business running Windows devices, servers, or Microsoft 365 that has not yet applied this month's updates.
We recommend applying this month's updates as soon as practical, prioritising internet-facing servers and any device running Exchange Server. Managed clients will receive these updates through our standard patching cycle; contact us if you would like this brought forward.
Source: Microsoft Community Hub