Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • Microsoft Patch Tuesday February 2018 current page
Link copied

Microsoft Patch Tuesday February 2018

Feb 14, 2018
Author:
400x400 Linkedin X Profile
Phantom Labs™
BeyondTrust
Blog banner default
Microsoft Patch Tuesday February 2018
400x400 Linkedin X Profile
Phantom Labs™
BeyondTrust

Patch Tuesday

Welcome back to the February 2018 Patch Tuesday. Microsoft has released patches for the Windows Kernel, StructuredQuery, and a host of the usual suspects. In all, there are fixes for 55 known vulnerabilities in this month’s update. Many of the vulnerabilities fixed have a ‘Critical’ security rating, including the Adobe Flash Security Update which fixes a vulnerability that was exploited in the wild. One vulnerability (CVE-2018-0771) was publicly disclosed prior to patching, but it is only rated at a moderate severity.

Kernel

The Windows Kernel has received a handful of fixes. The vulnerabilities that these fixes patch allow for a successful exploit to elevate an attacker’s privileges on a system and disclose sensitive information that could further compromise an affected system. The vulnerabilities revolve around object memory mismanagement at the kernel level. Microsoft rates these vulnerabilities as “Important.”

Scripting Engine

The Scripting Engine has 11 Critical vulnerabilities and 1 Important vulnerability patched this month. The engine is responsible for some object memory management in Microsoft Edge. When that engine mismanages maliciously crafted content, the Edge browser could be leveraged to execute an attacker’s code remotely. None of these vulnerabilities were known to be exploited or disclosed before the patch was made available.

Office

Office makes its regular Patch Tuesday appearance. This month Outlook contains a Critical remote code execution vulnerability. An attacker would exploit this vulnerability by convincing the user to open a maliciously crafted attachment in an affected version of Microsoft Outlook, and then after opening it the attacker’s code would be executed. Excel also has a remote code execution vulnerability, but it is only rated as Important. The code would have the same security context as Outlook or Excel, giving us a gentle reminder to exercise the principal of least privilege.

Edge and Internet Explorer

Microsoft’s browsers make the usual appearance, but this time with some interesting flare. One vulnerability for Edge was disclosed prior to patching that would allow for security features in the browser to be bypassed by attackers. To Microsoft’s knowledge, there have been no exploits of this vulnerability in the wild. Both Edge and Internet Explorer contain Information Disclosure vulnerabilities that would give an attacker access to potentially sensitive information on the system. One of these information disclosure vulnerabilities was rated as Critical by Microsoft, the rest are rated as Important.

Adobe Flash Player

Adobe has released a fix for a Remote Code Execution vulnerability that was being exploited in the wild. The attack is being used in limited, targeted attacks against Windows users. The attacks are known to leverage Office documents with embedded malicious Flash content that are distributed via email. Microsoft rates this vulnerability as Critical, and users should be advised to apply the patch as soon as possible.

Latest Posts
  • Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Jun 12, 2026 Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Blog
    7m
  • Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Jun 9, 2026 Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Blog
    6m
  • Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Jun 8, 2026 Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Blog
    5m
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
Related
  • Root Security in Linux: Understanding the Three Maturity Levels
    Feb 7, 2025 Root Security in Linux: Understanding the Three Maturity Levels
    Blog
    3m
  • Passwordless Administration Explained
    Jul 6, 2020 Passwordless Administration Explained
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.