What happened
Microsoft released an extensive security update addressing a record 974 vulnerabilities across its software portfolio. Among these, two flaws affecting Microsoft Windows have been actively exploited in the wild. The vulnerabilities span multiple components, with 723 found in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Of the total, over 110 have been classified as critical severity, indicating a significant risk to affected environments. The detected exploitation of the Windows flaws highlights the urgency for organisations to review their security postures in response to these vulnerabilities.
Who is affected
Organisations running Microsoft Windows are impacted by these vulnerabilities, especially those systems where the vulnerabilities have been actively exploited. Affected deployments may include environments relying on Windows operating systems that have not yet been patched or mitigated. The vulnerabilities’ widespread nature suggests that any organisation utilizing Windows could potentially be exposed to potential exploitation, particularly where security controls do not adequately thwart malicious activity targeting these flaws.
Recommended actions
- Apply the latest security updates from Microsoft immediately, prioritising patches that address the reported actively exploited Windows flaws.
- Verify the application of security patches across all Windows systems to ensure that the vulnerabilities are mitigated.
- Implement network monitoring for indicators of compromise associated with active exploitation of these vulnerabilities, especially on systems with externally facing services.
- Review and strengthen endpoint security controls, including intrusion detection and prevention systems, to better detect reconnaissance or exploitation attempts.
- Maintain an active security posture by monitoring for further updates from Microsoft concerning ongoing or new vulnerabilities related to these flaws.
Indicators of compromise
No specific indicators of compromise have been supplied at this time.

