Web_Logo
Remote Support
Microsoft Windows: Patch Now, Attackers Exploiting Flaws
Home » Microsoft Updates  »  Microsoft Windows: Patch Now, Attackers Exploiting Flaws

Microsoft Windows: Patch Now, Attackers Exploiting Flaws

Microsoft's August security update fixes several critical Windows vulnerabilities, and one is already being used in live attacks.

  • What it is: A flaw in the Windows network component (WinSock) is being actively exploited to gain full system-level access. Two further critical flaws affect Windows Active Directory Certificate Services and Windows DHCP Server, both allowing remote code execution.
  • Who is affected: Any Windows server or workstation that has not yet installed this month's security update, particularly on-premises servers running Active Directory or DHCP.
  • The risk: The actively exploited flaw lets an attacker who already has a foothold escalate to full control of the machine. The Active Directory and DHCP flaws can be triggered remotely with little to no user interaction.
  • What to do: Install this month's Windows security updates as a priority, particularly on any server running Active Directory Certificate Services or DHCP.

We recommend treating this month's patching as urgent rather than routine, especially for on-premises servers.