Microsoft Reveals Four Zero-Day Vulnerabilities in Latest September Update

Published:

spot_img

Microsoft’s September Patch Update Reveals Active Exploitation of Critical Vulnerabilities

Hackers are wasting no time in exploiting critical vulnerabilities identified in Microsoft’s latest security update. Out of the 79 flaws addressed by Microsoft, four are already being actively targeted by attackers.

Two of the zero-day bugs allow cybercriminals to bypass key security protections in Windows, making them a top priority for organizations to address. Another zero-day flaw grants unauthorized access to system-level privileges, while the fourth bug reintroduces vulnerabilities in certain versions of Windows 10 that were previously patched by Microsoft.

In total, Microsoft’s September update included seven critical vulnerabilities that could enable remote code execution and elevation of privilege attacks. The company highlighted 19 CVEs in the update as particularly risky, as they facilitate remote code execution with minimal complexity, require no user interaction, and impact widely-used products.

Among the notable vulnerabilities are CVE-2024-38226, affecting Microsoft Publisher, which allows attackers to bypass Office macros for blocking malicious files. Another bug, CVE-2024-43491, poses a high-severity risk by rolling back previous security fixes in Windows 10, potentially exposing users to exploitation.

Security experts emphasize the importance of promptly addressing these vulnerabilities to prevent malicious activities. With a total of 745 vulnerabilities disclosed by Microsoft this year, organizations must remain vigilant in applying patches and safeguarding their systems against cyber threats.

spot_img

Related articles

Recent articles

Hefring Marine Unveils All-in-One Fleet Management App

Navigating New Waters: Hefring Marine’s Innovative App Revolutionizes Fleet Management In an ever-evolving maritime landscape, the need for efficient fleet management has become paramount. Hefring...

Experts Warn About Serious New Vulnerability in Windows

Critical Windows Vulnerability Raises Alarms Among Experts A newly identified vulnerability in Windows is making waves in the cybersecurity community, prompting urgent calls for action...

Qatar Unveils New School Calendar Through 2028: Extended Ramadan Breaks, Long Weekends, and Additional Holidays

Qatar's Innovative Academic Calendar: A Focus on Student Well-being Qatar has recently unveiled a new academic calendar that significantly enhances the educational landscape for students....

Anatsa Android Banking Trojan Affects 90,000 Users via Fake PDF App on Google Play

Rise of the Anatsa Banking Trojan: A New Threat in Cybersecurity Overview of the Anatsa Malware Campaign Recent investigations have unveiled a troubling campaign involving a...