Skip to main content
  1. Home
  2. Computing
  3. Legacy Archives

Microsoft overlooks four Stuxnet zero-day bugs in Patch Tuesday

Add as a preferred source on Google

Despite a larger than usual Patch Tuesday addressing 13 vulnerabilities yesterday, Microsoft appears to have left out a few vulnerabilities that the Stuxnet worm exploits. First publicized in July attacking vulnerable systems via a Windows shortcut bug, Stuxnet apparently uses four additional zero-day bugs and two stolen digital certificates to game the OS’s escalation of privileges system, according to security researchers at Kaspersky Labs.

Yesterday’s Patch Tuesday was also notable because it included four critical updates for XP. A previously-known Stuxnet-exploit in Windows’ Print Spooler service was part of yesterday’s Patch Tuesday group. The Windows shortcut issue was patched in August.

Recommended Videos

The latest vulnerability that Stuxnet has been exploiting involves yet another bug in Windows’ Print Spooler service.  This vulnerability affects Windows XP, Windows Vista, Windows 7, Windows Server 2008, and Windows Server 2008 R2, according to Microsoft. The attacker can take control of a computer by sending a specially crafted print request to a vulnerable system where the print spooler service is exposed without authentication.

Microsoft rated the hole  “critical” for Windows XP but only “important” for the other supported versions of Windows.

Microsoft will be addressing these isses.

“These are local EoP issues which means that an attacker, in this case Stuxnet, already has permission to run code on the system or has compromised the system through some other means,” wrote Jerry Bryant, group manager of Microsoft’s Response Commuications on the blog.

First reported by security vendor VirusBlokAda, the worm targeted Siemens’ Simatic WinCC and PCS 7 software, which run on industrial control systems. This has minimized the worm outbreak, as most operators separate the control network from business and public networks.

Fahmida Y. Rashid
Former Digital Trends Contributor
TSMC might set up a price hike that could come straight for your next phone, laptop, or tablet
Here's what TSMC's rumored 10% chip price increase actually means in dollar terms, and why your next phone or laptop could end up costing more.
TSMC Fab

My wallet flinched the second I saw the words "TSMC" and "price increase" in the same headline, and honestly, yours should too.

Turns out the company behind the silicon powering basically every flagship device out there, including Apple’s A-series and Qualcomm’s Snapdragon processors, is reportedly about to make all of it a little pricier.

Read more
Apple fixes Hide My Email bug that exposed users’ real email addresses
Here's how Apple's Hide My Email flaw leaked real addresses for over a year, and why it only got fixed once the story went public.
apple-merging-sign-in-with-apple-hide-my-email-icloud+

Turns out the "Hide" part of Hide My Email wasn't doing its job quite as advertised, something that I covered early in July. Security researcher Tyler Murphy reported the flaw in June 2025, but despite Apple claiming it was resolved in March 2026, independent tests confirmed it remained exploitable, at least until July 3, 2026.

So how did this bug actually work?

Read more
Gemini Notebook’s new Collections arrive just as Google turns it into a bigger workspace
Google is cleaning up notebook organization as the former NotebookLM expands across Gemini and Search
Gemini Notebook branding on a MacBook

Google has barely finished renaming NotebookLM, and it’s already addressing one of the headaches that comes with building a large research library.

Collections are rolling out to all Gemini Notebook users, giving them a way to group related notebooks while keeping everything visible under My Notebooks. The dashboard gets some structure without asking users to rearrange the library they’ve already built.

Read more