Microsoft has released key security updates for Edge, Teams, and Skype to patch two zero-day vulnerabilities in open-source libraries.
The two zero-day vulnerabilities were discovered last month, and both bugs have been actively exploited to target individuals with spyware, according to researchers at Google and Citizen Lab.
The vulnerabilities were discovered in two common open source libraries, webp and libvpx.
In a brief statement, Microsoft said it had rolled out fixes addressing the two vulnerabilities in the webp and libvpx libraries.
“Microsoft is aware and has released patches associated with the two Open-Source Software security vulnerabilities, CVE-2023-4863 and CVE-2023-5217. Through our investigation, we found that these affect a subset of our products and we have addressed them in our products,” the company said in a security update.
While the CVE-2023-4863 security patch addressed the bug in Microsoft Edge, Microsoft Teams for Desktop, Skype for Desktop and Webp Image Extensions, the CVE-2023-5217 patch was issued for Microsoft Edge.
However, Microsoft declined to say if its products had been exploited in the wild, or if the company has the ability to know, reports TechCrunch.
Bijay Pokharel
Related posts
Recent Posts
Subscribe
Cybersecurity Newsletter
You have Successfully Subscribed!
Sign up for cybersecurity newsletter and get latest news updates delivered straight to your inbox. You are also consenting to our Privacy Policy and Terms of Use.