You are here

Microsoft Addresses RCE and Spoofing Vulnerabilities under Active Exploitation

Microsoft Addresses RCE and Spoofing Vulnerabilities under Active Exploitation

Created: Thursday, August 13, 2020 - 09:53
Categories:
Cybersecurity

The U.S. Department of Homeland Security Cybersecurity and Infrastructure Security Agency (CISA) advises that Microsoft has released security updates to address two vulnerabilities – CVE-2020-1380 and CVE-2020-1464 – that are being actively exploited. CVE-2020-1380 is a remote code execution vulnerability affecting Internet Explorer 11, and CVE-2020-1464 is a spoofing vulnerability that affects multiple Windows products. An attacker could exploit these vulnerabilities to take control of an affected system. CISA) encourages users and administrators to review Microsoft’s Security Advisories for CVE-2020-1380 and CVE-2020-1464 and apply the necessary updates. Read the advisory at CISA.