MICROSOFT is warning users to update their systems after a vulnerability has allegedly is being exploited by foreign hackers.

Experts are warning Windows users to update their computers after the “CVE-2021-44228” flaw in the software Apache Log4j was found as a vulnerability in credential-stealing malware.

Microsoft is warning users to update their PC immediately

1

Microsoft is warning users to update their PC immediatelyCredit: Getty

Log4J is not the only security threat that’s exposed to Windows users — millions of Windows 10 users now need to be aware of over 60 vulnerabilities that were found in Microsoft’s Patch Tuesday round.

International hackers are allegedly exploiting CVE-2021-43890 to install a malicious Emotet or Trickbot that’s designed to steal credentials.

Luckily, Microsoft found the bug and has fixed it – but you need to act now.

During the latest round of Microsoft’s Patch Tuesday round, over 60 vulnerabilities were found and fixed in its product range, including Windows, Visual Studio, Office, PowerShell and SharePoint Server.

Seven were given a critical rating, and six zero-days were fixed.

However, experts are still warning people to not delay installing the latest Windows update to ensure their device stays up to date.

Most read in Tech

The CVE-2021-43890 is a spoofing vulnerability in the Windows AppX installer that can be used to deliver pretty nasty malware.

This malicious software package gets installed unsuspectingly by users when they open infected documents and other material.

Those with admin account rights are most at risk – but like all other exploits, Windows is working to stop its detrimental effects from being even more widespread.

Microsoft itself has explained that the exploitation is in effect.

“Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as Emotet/Trickbot/Bazaloader,” the company said in a security guide.

“Given the critical nature of this vulnerability and the fact that there is active exploitation,” said Chad McNaughton, technical community manager at Automox, said, “organizations should take immediate action to remediate within the next 24 hours.”

Other remaining zero-day vulnerabilities were also found in Microsoft’s latest Patch Tuesday.

The majority affected Windows 10 and 11 users while some affected Windows Servers users.

Warning about FAKE Microsoft emails here are the red flags to watch to protect your device

We pay for your stories!

Do you have a story for The US Sun team?

This post first appeared on Thesun.co.uk

Leave a Reply

Your email address will not be published. Required fields are marked *

You May Also Like

IKEA’s Revamped AR App Lets You Design Entire Rooms

From there you can place furniture, shelving systems, decorations and change wall…

Netflix warns it will CHARGE users who share their passwords

NETFLIX on Tuesday announced that it will begin to charge users who…

18 cast-iron cannonballs from the Acre Bombarded battle in 1840 found in walls of Israeli museum

More than a dozen cast-iron cannonballs have been hiding in the walls…

The superblueberry! Scientists busy creating new fruit that’ll thrive even in a Scottish climate – and it’ll be the size of a STRAWBERRY

Scientists are creating a new variety of blueberry which will grow in…