Microsoft and Adobe have released more than 100 patches between them to address dozens of security flaws, many of them rated ‘critical', in the latest Patch Tuesday.
Microsoft's 53 patches address 20 rated critical covering its browsers Edge and Internet Explorer, as well as Office and, obviously, various iterations of the Windows operating system. There aren't, however, any zero-day security flaws that require an urgent patch, but four of them are publicly known, but not yet exploited.
Chris Goettl, manager of product management - security at Ivanti, provider of LanDesk, described Microsoft's Patch Tuesday action as "fairly tame".
He continued: "[There are] 47 total unique vulnerabilities resolved across 11 updates. Two of these have been publicly disclosed, which means enough information has been released to the public to allow a threat actor to create an exploit or at least giving them a jump start on where to begin.
"CVE-2017-11827 affects both IE and Edge. This vulnerability could be used in user targeted attacks, like a phishing email or exploiting a website, then convincing a user to open a malicious attachment or content.
"Once exploited the attacker would gain equal rights to the current user. If the user is a full administrator the attacker would gain control of the affected system.
"The second vulnerability (CVE-2017-11848) is an information disclosure vulnerability in Internet Explorer that could allow an attacker to track the navigation of the user leaving a maliciously crafted page," he warned.
Indeed, Greg Wiseman, a senior security researcher at security company Rapid7, pointed out that web browser issues account for two-thirds of Microsoft's patched vulnerabilities this month, with Edge out-scoring Internet Explorer two-to-one (24 to IE's 12).
He added: "No non-browser vulnerabilities are considered critical this month, but with a little bit of social engineering, an attacker could theoretically combine one of the Office-based RCE vulnerabilities, like CVE-2017-11878 or CVE-2017-11882, with a Windows kernel privilege escalation weakness, such as CVE-2017-11847, to gain complete control over a system.
"Thankfully, none of the patched vulnerabilities this time around are known to be exploited in the wild."
At least, not yet.
Adobe, meanwhile, offered up a treat of 83 patches, including five critical ones for the usually utterly secure Flash player. All five of these security flaws enable remote code execution in Adobe Flash if left unpatched.
Adobe's trove of patches also fix 62 security flaws in Acrobat and Acrobat Reader, including fixes for a plethora of remote code execution security flaws.
But that's not all!
A number of other items of Adobe software also require urgent fixes, including Photoshop, Adobe Digital Editions, Shockwave, InDesign and Connect. All have at least one flaw rated critical, so if you're running anything made by Adobe you basically need to get it patched as a matter of urgency.
Goettl also warned shoppers to be vigilante during the run-up to Christmas following the recent discovery of the KRACK vulnerability in the WPA Wifi security protocol.
"Pretty much any Wifi using the WPA or WPA2 encryption can be exploited. This means an attacker could eavesdrop on your connection and gain access to sensitive information, including username and password, credit card information, or any other personally identifiable information being transmitted over the Wifi unencrypted.
"This vulnerability was resolved in last month's Microsoft update, so be sure you have pushed out the October operating system updates.
"Also, your phones, routers, hotspots, even Wifi-enabled Internet of Things devices are likely exposed to this vulnerability [as well as] all the public Wifi networks you connect should be considered vulnerable as well.
"If you are going to do some online shopping from your phone, you may want to do it from the cellular network.
"If you do connect to a Wifi network that could be exposed make sure you only transact on sites that are encrypted (URL starts with [HTTPS://]HTTPS://) or as soon as you connect, establish a VPN connection to secure any transactions or data traffic you may be using."
In other words, let's be careful out there.
Claims to have "the most competitive logic density" in the industry
Dell's high-end mobile workstations upgraded with Intel Coffee Lake CPUs
Webstresser admins were also arrested in the UK, Croatia, Canada and Serbia
Security firm claims that 117,638 sites out of 135,035 analysed contain serious security flaws