Enhancing Linux Security with Live Patching

Publié le: 17 juin 2025
sur la chaîne: Ivanti
23
like

Enhancing Linux Security with Live Patching

➡️ Watch full clip here:    • May 2025 Patch Tuesday  
➡️ Register for Patch Tuesday Webinar Series: https://www.ivanti.com/lp/webinar-ser...
➡️ Download slides here: https://www.ivanti.com/resources/patc...

A partnership with Tux Care improves Linux workload uptime through live patching, enabling kernel updates without reboots. Awareness of vulnerabilities, especially regarding Ang OTP, is essential as patches have been available since late April. Vendor response times to vulnerabilities vary, with Cisco providing timely updates. Mitigation strategies include patching and workarounds. Additionally, vulnerabilities in Next.js and Apache Tomcat require immediate attention to maintain security.
Adobe announces important updates for its Creative Cloud Suite, targeting five critical vulnerabilities related to arbitrary code execution. Key applications like Adobe Bridge, Illustrator, InDesign, and Photoshop receive specific patches to improve security. Other applications, including Dreamweaver, also have vulnerabilities addressed, showcasing Adobe's commitment to enhancing software security across its platform.
Key Takeaways
Microsoft resolved 72 new CVEs, including five zero-day exploits.
Windows 11 and Server 2025 update for May includes three AI features and considerably larger installer size (~4GB).
Adobe released 13 updates resolving 39 CVEs, 33 of which are rated Critical.
May Patch Tuesday resolves five actively exploited and two publicly disclosed vulnerabilities. Spoiler alert: all five zero-days are resolved by deploying the Windows OS update. Also, this month Windows 11 and Server 2025 updates include some new AI features, but they carry a lot of baggage. Literally – they are around 4GB! New AI features include Recall, Click to Do and Improved Windows Search.
Microsoft has resolved a total of 72 new CVEs this month, six of which are rated Critical. The five zero-day vulnerabilities are rated Important, but using a risk-adjusted scoring model they would all be rated Critical.
Microsoft exploited vulnerabilities
Microsoft resolved an Elevation of Privilege vulnerability in Windows Ancillary Function Driver for WinSock (CVE-2025-32709) that could allow an attacker to elevate privileges locally to gain administrator privileges. The vulnerability affects Windows Server 2012 and later OS versions. The vulnerability is confirmed to be exploited in the wild. Microsoft severity is rated as Important and has CVSS 3.1 of 7.8. Risk-based prioritization warrants treating this vulnerability as Critical.
Microsoft resolved a pair of Elevation of Privilege vulnerabilities in Windows’ Common Log File System Drive (CVE-2025-32706 and CVE-2025-32701) that could allow an attacker to elevate privileges locally to gain SYSTEM privileges. The vulnerabilities affect all Windows OS versions. The vulnerabilities are confirmed to be exploited in the wild. Microsoft’s severity rating for both CVEs is Important and CVSS 3.1 of 7.8. Risk-based prioritization warrants treating these vulnerabilities as Critical.

Chapters:
0:00 - Tux Care Partnership
0:43 - Linux Vulnerabilities
1:12 - Vendor Response Times
2:12 - Mitigation Strategies
2:51 - Framework Vulnerabilities


Sur cette page du site, vous pouvez voir la vidéo en ligne Enhancing Linux Security with Live Patching durée heure minute seconde en bonne qualité , qui a été Téléchargé par l'utilisateur Ivanti 17 juin 2025, Partagez le lien avec vos amis et connaissances, sur youtube cette vidéo a déjà été regardée 23 fois et il a aimé like téléspectateurs. Bon visionnage!