Microsoft has made significant strides in enhancing the security of its operating systems with the August Patch Tuesday update, addressing an impressive 421 vulnerabilities across various products. Among these, a particularly concerning zero-day flaw has already been exploited in the wild, making it imperative for Windows users to prioritize this update.
This month’s patch targets multiple versions of Windows, including Windows 11 25H2/24H2, Windows 11 23H2, and Windows 10. The vulnerabilities span a wide array of Microsoft products, such as Office, Exchange, Azure, and SharePoint. However, the spotlight is on a critical flaw known as the “Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability.” This vulnerability poses a serious risk, as it allows an attacker to gain system privileges on a Windows PC without any user interaction, provided they already have lower-level access.
According to Action1, a patch management provider, “The primary threat is local privilege escalation.” An attacker with low-privileged access could exploit this vulnerability to gain extensive control over the affected system, potentially leading to unauthorized file access, deletion, malware installation, and even the creation of new user accounts. Although this vulnerability is rated as Important rather than Critical, its exploitation has been detected, underscoring the need for immediate action.
More zero-day flaws
In addition to the aforementioned vulnerability, the August patches also address two other zero-day flaws. One of these, the “Windows User Profile Service Elevation of Privilege Vulnerability,” could enable an attacker to gain administrative privileges on a compromised computer. While this flaw has not yet been exploited, it was publicly disclosed prior to the update, raising concerns about its potential for future exploitation.
As these Patch Tuesday updates are mandatory, they should automatically download and install on all supported PCs. Users are encouraged to verify that the update has been applied and to restart their computers to complete the process. For those still using Windows 10, enrollment in the free Extended Security Updates (ESU) program is necessary to continue receiving security patches.
While this month’s update addressed fewer vulnerabilities than July’s substantial patch, which resolved 570 flaws, Microsoft continues to demonstrate a robust commitment to security. The company has leveraged artificial intelligence in its efforts, utilizing an internal tool known as the “multi-model agentic scanning harness,” or MDASH. This AI-driven solution aims to identify genuine Windows vulnerabilities, minimize false positives, and expedite the reporting process to engineers, thereby reducing the window of opportunity for attackers to exploit zero-day flaws.
Minor improvements
Beyond the critical security enhancements, the August Patch Tuesday update introduces several minor improvements to core Windows features. Notably, File Explorer now displays the sizes of larger files in MB or GB, enhancing user experience. Additionally, middle-clicking a tab to open a new folder is now functional in both the address bar and Home page, and file thumbnails in the Recommended section have been made more legible.
Windows Hello has also received an upgrade, now supporting external fingerprint readers. This allows users to connect a fingerprint reader to their desktop PC for convenient sign-in. Furthermore, the Voice Access feature, which enables hands-free control of the PC via voice commands, has been enhanced with a new Voice Isolation capability designed to improve speech recognition by minimizing background noise.
For laptop users, two new touchpad controls have been introduced: one for adjusting scrolling speed and another for enabling accelerated scrolling, allowing for a more responsive navigation experience. These updates reflect Microsoft’s ongoing commitment to refining user experience while bolstering security measures across its platforms.