{"id":25760,"date":"2025-02-06T13:21:48","date_gmt":"2025-02-06T21:21:48","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2025\/02\/06\/news-19483\/"},"modified":"2025-02-06T13:21:48","modified_gmt":"2025-02-06T21:21:48","slug":"news-19483","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2025\/02\/06\/news-19483\/","title":{"rendered":"Il Patch Tuesday di gennaio con 159 CVE supera il record del singolo mese"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/01\/shutterstock_86010604.jpg\"\/><\/p>\n<p><strong>Credit to Author: Angela Gunn| Date: Thu, 16 Jan 2025 07:30:18 +0000<\/strong><\/p>\n<div class=\"entry-content lg:prose-lg mx-auto prose max-w-4xl\">\n<p>Marted\u00ec scorso Microsoft ha rilasciato 159 aggiornamenti che riguardano 13 famiglie di prodotti. Nove dei problemi affrontati sono considerati da Microsoft di gravit\u00e0 critica e 43 hanno un punteggio base CVSS pari o superiore a 8.0. Tre di essi sono soggetti a exploit in the wild. Uno di questi pu\u00f2 essere mitigato al meglio tramite la configurazione di Microsoft Outlook per la lettura di tutta la posta standard in formato testo.<\/p>\n<p>Questo elevato numero di aggiornamenti senza precedenti riguarda soprattutto Windows, con 132 patch applicabili al sistema operativo (il terzo rilascio pi\u00f9 importante dal 2020). (All&#8217;interno di questo gruppo, emergono diversi temi: 28 patch per l&#8217;esecuzione di codici remoti riguardanti Windows Telephony Services, ad esempio, o i 17 problemi di elevazione dei privilegi affrontati in Windows Digital Media. Otto delle patch di Windows sono classificate come critiche, tra cui il bug OLE di Outlook gi\u00e0 menzionato. (Analizzeremo pi\u00f9 da vicino questa situazione tra poco).<\/p>\n<p>Al momento del rilascio della patch, tre problemi EoP di gravit\u00e0 importante, tutti intitolati \u201cWindows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability\u201d, risultano essere sfruttati in the wild, mentre altri 17 CVE hanno maggiori probabilit\u00e0 di essere sfruttati nei prossimi 30 giorni, secondo le stime dell&#8217;azienda. Due dei problemi di questo mese possono essere rilevati dalle protezioni Sophos e le informazioni su di essi sono riportate nella tabella seguente.<\/p>\n<p>Leggi tutto <a href=\"https:\/\/news.sophos.com\/en-us\/2025\/01\/14\/159-cve-january-patch-tuesday-smashes-single-month-record\/\">l\u2019articolo<\/a>.<\/p>\n<div class=\"sharedaddy sd-sharing-enabled\">\n<div class=\"robots-nocontent sd-block sd-social sd-social-icon-text sd-sharing\">\n<h3 class=\"sd-title\">Share this:<\/h3>\n<div class=\"sd-content\">\n<ul>\n<li class=\"share-mastodon\"><a rel=\"nofollow noopener noreferrer\" data-shared=\"sharing-mastodon-959331\" class=\"share-mastodon sd-button share-icon\" href=\"https:\/\/news.sophos.com\/it-it\/2025\/01\/16\/il-patch-tuesday-di-gennaio-con-159-cve-supera-il-record-del-singolo-mese\/?share=mastodon\" target=\"_blank\" title=\"Click to share on Mastodon\" ><span>Mastodon<\/span><\/a><\/li>\n<li class=\"share-bluesky\"><a rel=\"nofollow noopener noreferrer\" data-shared=\"sharing-bluesky-959331\" class=\"share-bluesky sd-button share-icon\" href=\"https:\/\/news.sophos.com\/it-it\/2025\/01\/16\/il-patch-tuesday-di-gennaio-con-159-cve-supera-il-record-del-singolo-mese\/?share=bluesky\" target=\"_blank\" title=\"Click to share on Bluesky\" ><span>Bluesky<\/span><\/a><\/li>\n<li class=\"share-reddit\"><a rel=\"nofollow noopener noreferrer\" data-shared=\"\" class=\"share-reddit sd-button share-icon\" href=\"https:\/\/news.sophos.com\/it-it\/2025\/01\/16\/il-patch-tuesday-di-gennaio-con-159-cve-supera-il-record-del-singolo-mese\/?share=reddit\" target=\"_blank\" title=\"Click to share on Reddit\" ><span>Reddit<\/span><\/a><\/li>\n<li class=\"share-linkedin\"><a rel=\"nofollow noopener noreferrer\" data-shared=\"sharing-linkedin-959331\" class=\"share-linkedin sd-button share-icon\" href=\"https:\/\/news.sophos.com\/it-it\/2025\/01\/16\/il-patch-tuesday-di-gennaio-con-159-cve-supera-il-record-del-singolo-mese\/?share=linkedin\" target=\"_blank\" title=\"Click to share on LinkedIn\" ><span>LinkedIn<\/span><\/a><\/li>\n<li><a href=\"#\" class=\"sharing-anchor sd-button share-more\"><span>More<\/span><\/a><\/li>\n<li class=\"share-end\"><\/li>\n<\/ul>\n<div class=\"sharing-hidden\">\n<div class=\"inner\" style=\"display: none;\">\n<ul>\n<li class=\"share-tumblr\"><a rel=\"nofollow noopener noreferrer\" data-shared=\"\" class=\"share-tumblr sd-button share-icon\" href=\"https:\/\/news.sophos.com\/it-it\/2025\/01\/16\/il-patch-tuesday-di-gennaio-con-159-cve-supera-il-record-del-singolo-mese\/?share=tumblr\" target=\"_blank\" title=\"Click to share on Tumblr\" ><span>Tumblr<\/span><\/a><\/li>\n<li class=\"share-pocket\"><a rel=\"nofollow noopener noreferrer\" data-shared=\"\" class=\"share-pocket sd-button share-icon\" href=\"https:\/\/news.sophos.com\/it-it\/2025\/01\/16\/il-patch-tuesday-di-gennaio-con-159-cve-supera-il-record-del-singolo-mese\/?share=pocket\" target=\"_blank\" title=\"Click to share on Pocket\" ><span>Pocket<\/span><\/a><\/li>\n<li class=\"share-print\"><a rel=\"nofollow noopener noreferrer\" data-shared=\"\" class=\"share-print sd-button share-icon\" href=\"https:\/\/news.sophos.com\/it-it\/2025\/01\/16\/il-patch-tuesday-di-gennaio-con-159-cve-supera-il-record-del-singolo-mese\/#print\" target=\"_blank\" title=\"Click to print\" ><span>Print<\/span><\/a><\/li>\n<li class=\"share-email\"><a rel=\"nofollow noopener noreferrer\" data-shared=\"\" class=\"share-email sd-button share-icon\" href=\"mailto:?subject=%5BShared%20Post%5D%20Il%20Patch%20Tuesday%20di%20gennaio%20con%20159%20CVE%20supera%20il%20record%20del%20singolo%20mese&#038;body=https%3A%2F%2Fnews.sophos.com%2Fit-it%2F2025%2F01%2F16%2Fil-patch-tuesday-di-gennaio-con-159-cve-supera-il-record-del-singolo-mese%2F&#038;share=email\" target=\"_blank\" title=\"Click to email a link to a friend\" data-email-share-error-title=\"Do you have email set up?\" data-email-share-error-text=\"If you&#039;re having problems sharing via email, you might not have email set up for your browser. You may need to create a new email yourself.\" data-email-share-nonce=\"3635d0940f\" data-email-share-track-url=\"https:\/\/news.sophos.com\/it-it\/2025\/01\/16\/il-patch-tuesday-di-gennaio-con-159-cve-supera-il-record-del-singolo-mese\/?share=email\"><span>Email<\/span><\/a><\/li>\n<li class=\"share-end\"><\/li>\n<\/ul>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div><\/div>\n<p><a href=\"https:\/\/news.sophos.com\/it-it\/2025\/01\/16\/il-patch-tuesday-di-gennaio-con-159-cve-supera-il-record-del-singolo-mese\/\" target=\"bwo\" >http:\/\/feeds.feedburner.com\/sophos\/dgdY<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/01\/shutterstock_86010604.jpg\"\/><\/p>\n<p><strong>Credit to Author: Angela Gunn| Date: Thu, 16 Jan 2025 07:30:18 +0000<\/strong><\/p>\n<p>Tenetevi forte&#8230; e per il momento prendete in considerazione l&#8217;idea di leggere le vostre email in chiaro<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10377],"tags":[32297,129,10516,3495,32310,19245,11993,16771],"class_list":["post-25760","post","type-post","status-publish","format-standard","hentry","category-security","category-sophos","tag-cve-2025-21298","tag-featured","tag-microsoft","tag-microsoft-windows","tag-ole","tag-patch-tuesday","tag-rtf","tag-threat-research"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/25760","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=25760"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/25760\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=25760"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=25760"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=25760"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}