#ThePatchReport #ZeroDayInitiative #0day
Welcome to the May 2023 edition of the Patch Report - our brief look into the latest security updates from Microsoft, Adobe, and beyond. We have a small release from both Microsoft and Adobe, but we do have active attacks reported on the Windows Win32k component. Join us as we break down the release, delve into a couple of tin foil hat theories, and point out where enterprises should focus their attention.
You can read the full patch blog at:
https://www.zerodayinitiative.com/blo...
00:00 Introduction
00:30 Adobe patches for Substance 3D Painter
01:03 CVE-2023-29336 Active attacks in Win32k
01:29 CVE-2023-29325 Windows OLS code execution
01:53 CVE-2023-24941 Remote code execution in NFS
02:30 CVE-2023-24955 SharePoint fix Pwn2Own Vancouver
03:28 CVE-2023-24932 Secure Boof SFB
Additional configuration guidance for Secure Boot:
https://msrc.microsoft.com/blog/2023/...
03:59 Re-release of CVE-2022-26928
04:34 Wrap-up