Microsoft Releases Security Updates to Fix 97 Flaws, One Actively Exploited in Ransomware Attacks

Microsoft has once again released a set of crucial security updates to fix various vulnerabilities found in its software. As cybersecurity concerns continue to grow, these updates aim to safeguard systems and prevent malicious attacks. The latest set of security updates released by the tech giant fix nearly a hundred flaws, including one that has already been exploited.

Microsoft has released a new set of security updates aimed at fixing almost a hundred vulnerabilities that could lead to devastating attacks. These updates are designed to address the bugs found in various Microsoft software, which could be targeted by cybercriminals seeking to exploit these vulnerabilities.

The severity of the bugs ranges from critical to important. In total, seven bugs were given a critical rating, while 90 were rated as important. This means that these flaws could cause significant damage to individuals or organizations by allowing attackers to gain complete control over the system.

Types of vulnerabilities

The security updates aim to fix different types of vulnerabilities in Microsoft software, including remote code execution flaws and elevation of privilege vulnerabilities. Out of the 97 vulnerabilities, 45 were remote code execution flaws, while 20 were elevation of privilege vulnerabilities.

Active Exploitation of a Security Flaw

One of the security vulnerabilities found in Microsoft software has been actively exploited in ransomware attacks in the wild. The specific bug being referred to is CVE-2023-28252, which is a privilege escalation flaw in the Windows Common Log File System (CLFS) Driver. Attackers have been actively targeting this flaw to gain control of systems and deploy ransomware.

Repeated exploitation of a CLFS component flaw

CVE-2023-28252 is the fourth privilege escalation flaw in the CLFS component that has come under active abuse in the past year alone. This repeated exploitation of the same flaw highlights the importance of regular updates, as Microsoft continues to fix vulnerabilities as soon as they become aware of them.

Cybercrime group’s use of the vulnerability

According to a report by Kaspersky, a cybercrime group has been using the vulnerability to deploy Nokoyawa ransomware against small and medium-sized businesses in the Middle East, North America, and Asia. This highlights the need for constant vigilance and security updates to prevent such incidents from happening.

CISA’s action on the zero-day vulnerability

In response to the active exploitation of CVE-2023-28252, the Cybersecurity and Infrastructure Security Agency (CISA) added the Windows zero-day to its catalog of known exploited vulnerabilities (KEV). This requires Federal Civilian Executive Branch (FCEB) agencies to secure their systems by May 2, 2023.

There is an update on the WinVerifyTrust vulnerability. Microsoft has also updated its advisory for CVE-2013-3900, which is a WinVerifyTrust signature validation vulnerability, to include several Server Core installation versions. This vulnerability could allow attackers to execute arbitrary code on the system remotely.

In addition to the security updates, Microsoft has also released fixes for 26 vulnerabilities in its Edge browser over the past month. These fixes aim to address various security flaws in the browser and prevent potential attacks.

The regular security updates released by Microsoft aim to provide individuals and organizations with necessary protection against malicious cyberattacks. While the updates are important, it is imperative to remain vigilant and implement additional security measures to prevent security breaches. In the face of a persistent threat landscape, Microsoft will continue to update and improve its security measures to safeguard its users against cyber threats.

Explore more

AI Infrastructure Costs Drive a Shift to Hybrid Cloud Models

The sudden realization that the physical infrastructure required for generative artificial intelligence is fundamentally different from traditional software-as-a-service workloads has sent ripples through the global tech industry. For over a decade, the migration toward a cloud-first strategy seemed like an inevitable path for every modern enterprise, promising infinite scalability without the burden of maintaining heavy hardware. However, as the computational

How Secure Is Your Data Journey on Public Wi-Fi?

A single click on a smartphone in a crowded airport terminal initiates a sophisticated sequence of events that most users never fully consider while they are simply sipping their morning coffee or waiting for their next flight. This digital transmission does not simply vanish into the air; instead, it undergoes a transformation into complex radio frequency signals that must navigate

Smart 6G Boosts Medical Application Capacity by 40 Percent

The integration of sixth-generation wireless technology into modern healthcare infrastructures has fundamentally altered the paradigm of patient care by offering unprecedented bandwidth and latency improvements that were previously considered unattainable in dense urban environments. This leap in connectivity is not merely an incremental update but a structural revolution that addresses the growing demand for high-fidelity data transmission in real-time medical

Is X-VPN Truly Private? Inside the Big Four No-Logs Audit

The rapid escalation of sophisticated surveillance techniques in early 2026 has forced digital privacy tools to transition from simple marketing promises to verifiable technical realities that withstand the scrutiny of professional auditors. X-VPN recently responded to this growing demand for transparency by commissioning an extensive independent no-logs audit from a Big Four firm, marking a significant shift in how the

MoneyGram Launches MGUSD Stablecoin on Stellar Blockchain

The global financial landscape is currently undergoing a massive transformation where traditional money transfer services are merging with decentralized finance to solve long-standing liquidity issues and infrastructure gaps. For decades, moving money across borders involved a series of intermediary banks, high fees, and significant delays that disproportionately affected underbanked populations. However, the rise of blockchain technology has introduced a faster