Microsoft fixed 100+ security flaws in Windows and Office this month

Here is a 201-word summary of the news article: Microsoft has released a significant number of security updates this month, fixing over 100 vulnerabilities across its Windows and Office products. The updates cover a range of critical issues, including remote code execution (RCE) flaws in Windows' Graphics Device Interface API and Windows Graphics Component, as well as several vulnerabilities in the Hyper-V virtualization software. Several of the Windows vulnerabilities are considered high-risk, including 12 flaws in the Routing and Remote Access Service (RRAS), half of which are RCE vulnerabilities. Microsoft has also addressed a medium-risk vulnerability in Kerberos for Windows Server 2025 that could allow attackers to gain administrator rights for domains. In Microsoft Office, the company has fixed 18 vulnerabilities, 16 of which are RCE flaws. Four of these critical RCE bugs can be exploited through the preview window, even without the user opening the file. The Microsoft Edge browser has also received security updates, addressing several vulnerabilities in the Chromium base and fixing two Edge-specific issues in the mobile version. Users are advised to ensure their systems are up-to-date with the latest security patches to protect against these vulnerabilities, which are not currently being exploited in the wild.
Note: This is an AI-generated summary of the original article. For the full story, please visit the source link below.