Security
World-famous library is still battling to recover from an incident described as one of the worst in British history.
Researchers allege that bugs could allow adversaries to "inject malicious libraries into Microsoft's applications to gain entitlements and user-granted permissions".
CVE-2024-38063 lets unauthenticated attackers carry out remote code execution by "repeatedly sending IPv6 packets".
"Supply chains for local councils will always be the weakest link to be exploited by attackers looking for valuable information due to the vast number of services employed for operations."
The bugs include four publicly known flaws and six that have been exploited in the wild.
Cops claims the crook "essentially pioneered both the exploit kit and ransomware-as-a-service models".