Automatically translated.View original post

Wait and see what else you will see.

Microsoft released a total of 63 security updates (Patch Tuesday) for November 2025 covering multiple versions of Windows 11 with one Zero-Day vulnerability actually compromised.

.

They are listed as follows: Windows 11 KB5068861, KB5068865, KB5066835, KB5066793 and Windows 10 participating ESU KB5068781 projects.

.

There are a total of 4 Critical Vulnerabilities, divided into 2 Remote Code Execution - RCE vulnerabilities, 1 Elevation of Privilege vulnerability, and 1 Information Disclosure vulnerability.

.

A breakdown of the vulnerabilities that have been addressed is as follows:

- Elevation of Privilege vulnerability: 29 items

- Security Feature Bypass vulnerability: 2 items

- Remote Code Execution vulnerability: 16 items

- Information Disclosure: 11 items

- Denial of Service vulnerability: 3 items

- Spoofing vulnerability: 2 items

.

The figures do not include vulnerabilities that were patched earlier in the same month, such as Microsoft Edge and Mariner.

.

Simultaneously, other software manufacturers also issued security updates, including Adobe, Cisco, Fortinet, Google (Android), Ivanti, runC, QNAP, SAP and Samsung, with many fixing major vulnerabilities including multiple Zero-Days.

.

Administrators are advised to implement Windows updates and Microsoft products ASAP, specifically Zero-Day vulnerabilities and vulnerabilities that can be attacked remotely, with follow-up updates from other software manufacturers to prevent the risk of being compromised by these vulnerabilities.

.

Source: bleepingcomputer

# IT News # Includes IT matters # Cough to know # IT

2025/11/18 Edited to

... Read moreจากประสบการณ์ตรงในการดูแลระบบ IT ผมพบว่า "Patch Tuesday" ของ Microsoft รอบเดือนพฤศจิกายน 2025 นี้ มีความสำคัญอย่างยิ่ง เพราะมีการแก้ไขช่องโหว่หลากหลายถึง 63 รายการ รวมถึงช่องโหว่ Zero-Day ที่ถูกโจมตีจริง ช่วยเพิ่มความปลอดภัยอย่างมากเมื่อนำมาอัปเดตทันที สำหรับผู้ที่ใช้ Windows 11 และ Windows 10 ที่เข้าร่วมโครงการ ESU แนะนำให้ตรวจสอบหมายเลขอัปเดต KB5068861, KB5068865, KB5066835, KB5066793 และ KB5068781 เพื่อให้มั่นใจว่าได้รับการติดตั้งครบถ้วนและสมบูรณ์ ช่องโหว่ที่ได้รับการแก้ไขครอบคลุมหลายประเภท เช่น การรันโค้ดจากระยะไกล (RCE) ที่อันตรายมาก และช่องโหว่ยกระดับสิทธิ์ รวมทั้งหมดกว่า 29 รายการ ช่วยป้องกันการแทรกแซงจากผู้ไม่หวังดีและลดความเสี่ยงต่อระบบอย่างเต็มที่ นอกจากนี้ เราควรให้ความสำคัญกับการอัปเดตซอฟต์แวร์อื่นๆ อย่าง Adobe, Cisco หรือ Samsung เพราะแต่ละรายก็ปล่อยอัปเดตเพื่อแก้ไขช่องโหว่สำคัญเช่นกัน การติดตามและอัปเดตอย่างต่อเนื่องจึงเป็นวิธีป้องกันภัยไซเบอร์ที่ดีที่สุดในยุคนี้ ผมแนะนำให้ตั้งเวลารีบอัปเดตระบบทันทีที่สามารถทำได้ และติดตามข่าวสารเพิ่มเติมจากแหล่งข้อมูลเชื่อถือได้อย่าง bleepingcomputer รวมถึงควรมีการสำรองข้อมูลก่อนการอัปเดตเพื่อลดความเสี่ยงกับข้อมูลสำคัญขององค์กรครับ