City
Epaper

Microsoft fixes 2 critical zero-day bugs in Edge, Teams, Skype

By IANS | Updated: October 5, 2023 11:45 IST

San Francisco, Oct 5 Tech giant Microsoft has released key security updates for Edge, Teams, and Skype to ...

Open in App

San Francisco, Oct 5 Tech giant Microsoft has released key security updates for Edge, Teams, and Skype to patch two zero-day vulnerabilities in open-source libraries.

The two zero-day vulnerabilities were discovered last month, and both bugs have been actively exploited to target individuals with spyware, according to researchers at Google and Citizen Lab.

The vulnerabilities were discovered in two common open source libraries, webp and libvpx.

In a brief statement, Microsoft said it had rolled out fixes addressing the two vulnerabilities in the webp and libvpx libraries.

“Microsoft is aware and has released patches associated with the two Open-Source Software security vulnerabilities, CVE-2023-4863 and CVE-2023-5217. Through our investigation, we found that these affect a subset of our products and we have addressed them in our products,” the company said in a security update.

While the CVE-2023-4863 security patch addressed the bug in Microsoft Edge, Microsoft Teams for Desktop, Skype for Desktop and Webp Image Extensions, the CVE-2023-5217 patch was issued for Microsoft Edge.

However, Microsoft declined to say if its products had been exploited in the wild, or if the company has the ability to know, reports TechCrunch.

Last month, Google patched a zero-day vulnerability in Chrome that was exploited by a commercial spyware vendor.

Apple also fixed two zero-day vulnerabilities actively being used to deliver Israel-based NSO Group’s Pegasus spyware on iPhones.

Internet watchdog group Citizen Lab, while checking the device of an individual employed by a Washington D.C.-based civil society organisation with international offices, had found the zero-click vulnerability.

Citizen Lab immediately disclosed the findings to Apple and assisted in their investigation.

Apple issued two CVEs related to this exploit chain (CVE-2023-41064 and CVE-2023-41061).

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Open in App

Related Stories

EntertainmentVijay Deverakonda announces new film with director Shouryuv, shares powerful first poster

NationalSale of property cannot be imposed as bail condition: Supreme Court

BusinessFrom uncertainty to discovery: Union Minister Hardeep Singh highlights India's 'data-first' strategy to unlock offshore energy wealth

Politics"Women of our state condemn this": Arunachal CM blames oppn for not favouring Constitution 131st Amendment Bill

InternationalIranian gunboats fire on tanker in Strait of Hormuz: UK authority

Technology Realted Stories

TechnologyOver 17.25 lakh 5-kg LPG cylinders sold since March 23: Govt

TechnologyCentre announces maritime insurance pool worth 12,980 crore to protect Indian vessels

TechnologyCabinet okays continuation of PMGSY-III till March 2028 with revised Rs 83,977 crore outlay

TechnologyCabinet approves 2 pc Dearness Allowance hike for Central government employees

TechnologyIndia moves beyond ‘blind exploration’, adopts data-led approach: Hardeep Puri