// ZDNET — HARDWARE & GADGET
Microsoft fixes 421 bugs and a Windows zero-day in August Patch Tuesday - update ASAP
Follow ZDNET: Add us as a preferred source on Google.
Microsoft continues its onslaught against security vulnerabilities, fixing a whopping 421 bugs in August's Patch Tuesday update. But looking beyond the sheer number, Windows users should install this month's update, as it patches a zero-day flaw that's already been exploited by attackers.
Aimed at Windows 11 25H2/24H2, Windows 11 23H2, and Windows 10, the 421 vulnerabilities encompass a range of Microsoft products, including Office, Exchange, Azure, and SharePoint. But it's the Windows patches that clobber the exploited zero-day. In technical jargon, Microsoft titles this flaw a "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability." What that means isn't as important as what it could do.
Also: A developer got Word 1.1a from 1990 to run on Windows 11 - try it yourself
By exploiting this bug, an attacker could gain system privileges on a Windows 11 or 10 PC without any interaction on the user's part. The person would already need lower-level access to the PC from an initial intrusion. But from there, system privileges would give the attacker the ability to view or delete your files, compromise your security, create user accounts, install malware, and enlist your PC in a botnet.
"The primary threat is local privilege escalation," patch management provider Action1 said in a post on the latest update. "An attacker who already has low-privileged access could exploit the vulnerability to gain SYSTEM privileges, potentially obtaining extensive control over the affected Windows system. Exploitation has been detected in the wild, so deployment should be prioritized even though the vulnerability is rated Important rather than Critical."
The August patches also squash two other zero-day flaws. One, labeled Windows User Profile Service Elevation of Privilege Vulnerability, could allow an attacker to gain administrative privileges on a compromised computer. Though this one hasn't yet been exploited in the wild, it was publicly known before this month's update, and Microsoft says that exploitation is more likely.
Since the Patch Tuesday updates are mandatory, they should automatically download and install on all supported PCs. But you still should double-check if only to restart your computer to complete the process.
Also: I read Microsoft's Windows 11 'quality' progress report - and the subtext says it all
In Windows 11, head to Settings and select Windows Update. Click the Check for updates button and reboot your PC when prompted. If you're still on Windows 10, you do need to be enrolled in the free Extended Security Updates (ESU) program to continue receiving security patches. In that case, go to Settings, select Update & Security, and then click Windows Update.