{"id":87113,"date":"2022-04-13T03:36:43","date_gmt":"2022-04-13T05:36:43","guid":{"rendered":"https:\/\/teknomers.com\/fr\/microsoft-publie-des-correctifs-pour-2-windows-zero-days-et-126-autres-vulnerabilites\/"},"modified":"2022-04-13T03:36:46","modified_gmt":"2022-04-13T05:36:46","slug":"microsoft-publie-des-correctifs-pour-2-windows-zero-days-et-126-autres-vulnerabilites","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/microsoft-publie-des-correctifs-pour-2-windows-zero-days-et-126-autres-vulnerabilites\/","title":{"rendered":"Microsoft publie des correctifs pour 2 Windows Zero-Days et 126 autres vuln\u00e9rabilit\u00e9s"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>Les mises \u00e0 jour Patch Tuesday de Microsoft pour le mois d&#8217;avril ont r\u00e9solu un <a rel=\"nofollow noopener\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2022-Apr\" target=\"_blank\">total de 128 vuln\u00e9rabilit\u00e9s de s\u00e9curit\u00e9<\/a> couvrant l&#8217;ensemble de son portefeuille de produits logiciels, notamment Windows, Defender, Office, Exchange Server, Visual Studio et Print Spooler, entre autres.<\/p>\n<p>10 des 128 bogues corrig\u00e9s sont class\u00e9s critiques, 115 sont class\u00e9s importants et trois sont class\u00e9s de gravit\u00e9 mod\u00e9r\u00e9e, l&#8217;un des d\u00e9fauts \u00e9tant r\u00e9pertori\u00e9 comme publiquement connu et un autre faisant l&#8217;objet d&#8217;une attaque active au moment de la publication.<\/p>\n<p>Les mises \u00e0 jour s&#8217;ajoutent \u00e0 <a rel=\"nofollow noopener\" href=\"https:\/\/docs.microsoft.com\/en-us\/deployedge\/microsoft-edge-relnotes-security\" target=\"_blank\">26 autres d\u00e9fauts<\/a> r\u00e9solu par Microsoft dans son navigateur Edge bas\u00e9 sur Chromium depuis le d\u00e9but du mois.<\/p>\n<p>La faille activement exploit\u00e9e (<a rel=\"nofollow noopener\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-24521\" target=\"_blank\">CVE-2022-24521<\/a>, score CVSS : 7,8) concerne une vuln\u00e9rabilit\u00e9 d&#8217;\u00e9l\u00e9vation des privil\u00e8ges dans le syst\u00e8me de fichiers journaux Windows Common (CLFS).  L&#8217;Agence am\u00e9ricaine de s\u00e9curit\u00e9 nationale (NSA) et les chercheurs de CrowdStrike Adam Podlosky et Amir Bazine sont cr\u00e9dit\u00e9s d&#8217;avoir signal\u00e9 la faille.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/backhub-dm3\" target=\"_blank\" title=\"CyberSecurity\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/02\/Les-logiciels-malveillants-piratant-les-medias-sociaux-se-propagent-via.png\" width=\"300\" height=\"250\" \/><\/a><\/div>\n<p>La deuxi\u00e8me faille zero-day publiquement connue (<a rel=\"nofollow noopener\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-26904\" target=\"_blank\">CVE-2022-26904<\/a>score CVSS\u00a0: 7,0) concerne \u00e9galement un cas d&#8217;\u00e9l\u00e9vation de privil\u00e8ges dans le service de profil utilisateur Windows, dont l&#8217;exploitation r\u00e9ussie &#8220;n\u00e9cessite qu&#8217;un attaquant gagne une condition de concurrence&#8221;.<\/p>\n<p>D&#8217;autres failles critiques \u00e0 noter incluent un certain nombre de failles d&#8217;ex\u00e9cution de code \u00e0 distance dans RPC Runtime Library (<a rel=\"nofollow noopener\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-26809\" target=\"_blank\">CVE-2022-26809<\/a>score CVSS\u00a0: 9,8), syst\u00e8me de fichiers r\u00e9seau Windows (<a rel=\"nofollow noopener\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-24491\" target=\"_blank\">CVE-2022-24491<\/a> et <a rel=\"nofollow noopener\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-24497\" target=\"_blank\">CVE-2022-24497<\/a>scores CVSS : 9,8), Service Windows Server (<a rel=\"nofollow noopener\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-24541\" target=\"_blank\">CVE-2022-24541<\/a>), Windows PME (<a rel=\"nofollow noopener\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-24500\" target=\"_blank\">CVE-2022-24500<\/a>) et Microsoft Dynamics 365 (<a rel=\"nofollow noopener\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-23259\" target=\"_blank\">CVE-2022-23259<\/a>).<\/p>\n<p>Microsoft a \u00e9galement corrig\u00e9 jusqu&#8217;\u00e0 18 failles dans Windows DNS Server, une faille de divulgation d&#8217;informations et 17 failles d&#8217;ex\u00e9cution de code \u00e0 distance, qui ont toutes \u00e9t\u00e9 signal\u00e9es par le chercheur en s\u00e9curit\u00e9 Yuki Chen.  15 failles d&#8217;escalade de privil\u00e8ges dans le composant Windows Print Spooler ont \u00e9galement \u00e9t\u00e9 corrig\u00e9es.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/cs-feb-header\" target=\"_blank\" title=\"CyberSecurity\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/03\/1647417170_810_Facebook-frappe-dune-amende-de-186-millions-de-dollars-GDPR.jpeg\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>Les correctifs arrivent une semaine apr\u00e8s que le g\u00e9ant de la technologie a annonc\u00e9 son intention de mettre \u00e0 disposition une fonctionnalit\u00e9 appel\u00e9e AutoPatch en juillet 2022 qui permet aux entreprises d&#8217;acc\u00e9l\u00e9rer l&#8217;application des correctifs de s\u00e9curit\u00e9 en temps opportun tout en mettant l&#8217;accent sur l&#8217;\u00e9volutivit\u00e9 et la stabilit\u00e9.<\/p>\n<h3>Correctifs logiciels d&#8217;autres fournisseurs<\/h3>\n<p>En plus de Microsoft, des mises \u00e0 jour de s\u00e9curit\u00e9 ont \u00e9galement \u00e9t\u00e9 publi\u00e9es par d&#8217;autres fournisseurs pour corriger plusieurs vuln\u00e9rabilit\u00e9s, \u00e0 savoir \u2014<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/04\/microsoft-issues-patches-for-2-windows.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Les mises \u00e0 jour Patch Tuesday de Microsoft pour le mois d&#8217;avril ont r\u00e9solu un total de 128 vuln\u00e9rabilit\u00e9s de s\u00e9curit\u00e9 couvrant l&#8217;ensemble de son portefeuille de produits logiciels, notamment Windows, Defender, Office, Exchange Server, Visual Studio et Print Spooler, entre autres. 10 des 128 bogues corrig\u00e9s sont class\u00e9s critiques, 115 sont class\u00e9s importants et [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":87114,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[246,4168,15954,4158,4165,4161,133,4157,4159,4171,4170,4167,8362,4160,4163,4162,185,2212,4172,4169,4166,4164,12365,45020,40604],"class_list":["post-87113","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-autres","tag-comment-pirater","tag-correctifs","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-des","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-logiciel-malveillant-de-ransomware","tag-microsoft","tag-mises-a-jour-de-la-cybersecurite","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-pour","tag-publie","tag-securite-informatique","tag-securite-internet","tag-violation-de-donnees","tag-vulnerabilite-logicielle","tag-vulnerabilites","tag-windows","tag-zerodays"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/87113","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=87113"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/87113\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/87114"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=87113"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=87113"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=87113"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}