July’s Microsoft Patch Tuesday addressed a record-breaking 570 security vulnerabilities, far surpassing previous months, with 59 rated CRITICAL. Of those critical ones, 48 enabled remote code execution and 9 allowed attackers to obtain system privileges. Overall, 145 of the 570 flaws (over 25%) enabled remote code execution, and 254 (45%) allowed unprivileged attackers to escalate to root system access.
Each of the past three months has broken Microsoft’s all-time security vulnerability patch record by significant and growing margins, indicating no restriction on the rate of discovery and disclosure. The host predicts that while many patches will continue next month, the counts will start to drop off, though future AI model improvements may unearth more subtle flaws, preventing a drop to zero soon.
July, following June’s 200 flaws, is suspected to be the all-time motherlode of vulnerabilities. Three weeks from the podcast date will reveal if this prediction holds true regarding declining patch volumes.