Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • November 2018 Patch Tuesday current page
Link copied

November 2018 Patch Tuesday

Nov 16, 2018
Author:
400x400 Linkedin X Profile
Phantom Labs™
BeyondTrust
Blog banner default
November 2018 Patch Tuesday
400x400 Linkedin X Profile
Phantom Labs™
BeyondTrust

Patch Tuesday

Welcome back to this month’s Patch Tuesday. Microsoft has patched 62 vulnerabilities this month, including two that had details disclosed prior to patching, and one “zero-day” vulnerability in Windows that was actively being exploited. The bulk of the vulnerabilities focus on web browsers.

Internet Explorer and Edge

Microsoft’s browsers received a host of fixes this month. Eight vulnerabilities in the Chakra Scripting Engine were patched for Internet Explorer and Edge. Attackers may be able to execute arbitrary code by luring a victim to a website hosting maliciously crafted content. Attackers would gain the same user rights as the current user.

Kernel

Like last month, a vulnerability in the Windows Kernel was patched that was actively being exploited. The attacker would have to have been logged into the system, but it would allow them to elevate their privileges to system level. Attackers leveraged this vulnerability against Windows 7 and Server 2008 targets in the wild.

Office

As usual, MS Office was host to many vulnerabilities that were patched this month. Over 20 vulnerabilities were addressed in this month’s patches. Attackers exploiting these vulnerabilities could gain access to sensitive information, execute code with privileges equal to that of the current user, and cause denial of service conditions.

Adobe Flash Player

Adobe Flash Player was patched for an Out-of-Bounds read vulnerability that could allow for remote code execution. As usual, Microsoft has bundled the patch with their update service due to the frequency of discovery of Adobe Flash player vulnerabilities.

Bitlocker

A previously disclosed vulnerability in Windows Bitlocker encryption technology was patched this month. Attackers exploiting the vulnerability would have been able to bypass the encryption features to access protected data. Specifically, SSDs that were encrypted using BitLocker were suspended in a state that, if found powered off, would be readable without decryption.

Latest Posts
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
  • How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    May 21, 2026 How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    Blog
    5m
  • Cybersecurity as a Boardroom Priority for Major African TelCos
    May 12, 2026 Cybersecurity as a Boardroom Priority for Major African TelCos
    Blog
    8m
Related
  • What Is RDP & How Do You Secure (or Replace) It?
    Oct 13, 2021 What Is RDP & How Do You Secure (or Replace) It?
    Blog
    1m
  • Learn what EMOTET is & How to Protect Against “The World’s Most Dangerous Malware”
    Aug 4, 2021 Learn what EMOTET is & How to Protect Against “The World’s Most Dangerous Malware”
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.