Close Menu
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

What's On

Google IO 2025 live keynote: all the latest on Gemini AI, Android 16 and more

20 May 2025

‘A Billion Streams and No Fans’: Inside a $10 Million AI Music Fraud Case

20 May 2025

Qualcomm’s Snapdragon 8 Elite 2 SoC to Launch Earlier Than Expected

20 May 2025
Facebook X (Twitter) Instagram
Just In
  • Google IO 2025 live keynote: all the latest on Gemini AI, Android 16 and more
  • ‘A Billion Streams and No Fans’: Inside a $10 Million AI Music Fraud Case
  • Qualcomm’s Snapdragon 8 Elite 2 SoC to Launch Earlier Than Expected
  • Stellar Blade Developer Plans To Release A Sequel Before 2027
  • You might want to wait to get your Nintendo Switch 2
  • What to Expect When You’re Convicted
  • MediaTek Showcases AI Strategy At Computex 2025, Unveils Hybrid Computing Solution
  • There’s A Demo For To A T, The Next Game From Katamari Damacy Creator, Out Now
Facebook X (Twitter) Instagram Pinterest Vimeo
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release
Subscribe
Best in TechnologyBest in Technology
Home » Google Fixes a Seventh Zero-Day Flaw in Chrome—Update Now
News

Google Fixes a Seventh Zero-Day Flaw in Chrome—Update Now

News RoomBy News Room1 December 20233 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email

Google’s Pixel devices have already received the November update, along with some additional fixes. The November Android Security Bulletin has also started to roll out to some of Samsung’s Galaxy line.

Microsoft

Microsoft has a Patch Tuesday every month, but November’s is worth notice. The update fixes 59 vulnerabilities, two of which are already being exploited in real-life attacks. Tracked as CVE-2023-36033, the first is an elevation of privilege vulnerability in Windows DWM Core Library marked as important, with a CVSS score of 7.8. “An attacker who successfully exploited this vulnerability could gain SYSTEM privileges,” Microsoft said.

Meanwhile, CVE-2023-36036 is an elevation of privilege vulnerability in Windows Cloud Files Mini Filter Driver with a CVSS score of 7.8. Also fixed in November’s update cycle is the already exploited libWep flaw previously fixed in Chrome and other browsers, which also impacts Microsoft’s Edge, tracked as CVE-2023-4863.

Another notable flaw is CVE-2023-36397, a remote code execution vulnerability in Windows Pragmatic General Multicast marked as critical with a CVSS score of 9.8. “When Windows message queuing service is running in a PGM Server environment, an attacker could send a specially crafted file over the network to achieve remote code execution and attempt to trigger malicious code,” Microsoft said.

Cisco

Enterprise software firm Cisco has issued fixes for 27 security flaws, including one rated as critical with a near maximum CVSS score of 9.9. Tracked as CVE-2023-20048, the vulnerability in the web services interface of Cisco Firepower Management Center Software could allow an authenticated, remote attacker to execute unauthorized configuration commands on a Firepower Threat Defense device managed by the FMC Software.

However, to successfully exploit the vulnerability, an attacker would need valid credentials on the FMC Software, Cisco said.

A further seven of the flaws fixed by Cisco are rated as having a high impact, including CVE-2023-20086—a denial-of-service flaw with a CVSS score of 8.6—and CVE-2023-20063, a code-injection vulnerability with a CVSS score of 8.2.

Atlassian

Atlassian has released a patch to fix a serious flaw already being used in real-life attacks. Tracked as CVE-2023-22518, the improper-authorization vulnerability issue in Confluence Data Center and Server is being used in ransomware attacks. “As part of Atlassian’s ongoing monitoring and investigation of this CVE, we observed several active exploits and reports of threat actors using ransomware,” it said.

Security outfit Trend Micro reported the Cerber ransomware group is using the flaw in attacks. “This is not the first time that Cerber has targeted Atlassian—in 2021, the malware re-emerged after a period of inactivity and focused on exploiting remote code execution vulnerabilities in Atlassian’s GitLab servers,” Trend Micro said.

All versions of Confluence Data Center and Server are affected by the flaw, which allows an unauthenticated attacker to reset Confluence and create an administrator account. “Using this account, an attacker can perform all administrative actions available to a Confluence instance administrator, leading to a full loss of confidentiality, integrity and availability,” Atlassian said.

SAP

Enterprise software giant SAP has released its November Security Patch Day, fixing three new flaws. Tracked as CVE-2023-31403 and with a CVSS score of 9.6, the most serious issue is an improper access control vulnerability flaw in SAP Business One. As a result of exploiting the issue, a malicious user could read and write to the SMB shared folder, the software giant said.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleAmazon’s ‘Q’ Is Less AI Conspiracy, More Corporate Chatbot
Next Article Sonic The Hedgehog 3 Resumes Production, Reveals New Look At Shadow

Related Articles

News

Google IO 2025 live keynote: all the latest on Gemini AI, Android 16 and more

20 May 2025
News

‘A Billion Streams and No Fans’: Inside a $10 Million AI Music Fraud Case

20 May 2025
News

You might want to wait to get your Nintendo Switch 2

20 May 2025
News

What to Expect When You’re Convicted

20 May 2025
News

NYT Strands today: hints, spangram and answers for Tuesday, May 20

20 May 2025
News

Review: Samsung Odyssey G8 QD-OLED Gaming Monitor

20 May 2025
Demo
Top Articles

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202494 Views

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 202486 Views

5 laptops to buy instead of the M4 MacBook Pro

17 November 202460 Views

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Latest News
News

What to Expect When You’re Convicted

News Room20 May 2025
Phones

MediaTek Showcases AI Strategy At Computex 2025, Unveils Hybrid Computing Solution

News Room20 May 2025
Gaming

There’s A Demo For To A T, The Next Game From Katamari Damacy Creator, Out Now

News Room20 May 2025
Most Popular

The Spectacular Burnout of a Solar Panel Salesman

13 January 2025120 Views

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202494 Views

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 202486 Views
Our Picks

Stellar Blade Developer Plans To Release A Sequel Before 2027

20 May 2025

You might want to wait to get your Nintendo Switch 2

20 May 2025

What to Expect When You’re Convicted

20 May 2025

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us
© 2025 Best in Technology. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.