Microsoft’s December 2024 Patch Tuesday Addresses 70 CVEs

Published:

spot_img

Microsoft’s December 2024 Patch Tuesday: Addressing Critical Vulnerabilities and Zero-Day Flaws

Microsoft’s December Patch Tuesday: A Year-End Security Overhaul

In a significant year-end update, Microsoft has rolled out its December Patch Tuesday, addressing a staggering 71 newly identified vulnerabilities across its product suite. This marks the last patch of 2024, a year that has already seen the company tackle a record-breaking 1,009 Common Vulnerabilities and Exposures (CVEs), the second-highest annual total in Patch Tuesday history.

Among the critical issues resolved this month is CVE-2024-49138, a zero-day vulnerability in the Windows Common Log File System (CLFS) driver. This flaw has been actively exploited, allowing attackers to gain SYSTEM-level privileges, making it particularly dangerous. Classified as a heap-based buffer overflow, CVE-2024-49138 is the ninth CLFS-related vulnerability addressed this year and has been rated as “important” with a CVSSv3 score of 7.8.

The December update also tackled a range of other vulnerabilities, including 30 remote code execution flaws and 27 elevation of privilege issues. Notably, CVE-2024-49070, a remote code execution vulnerability in Microsoft SharePoint, was also patched, alongside critical flaws in Microsoft Message Queuing and Remote Desktop Services.

Cybersecurity experts emphasize the urgency of these updates, especially with ransomware operators increasingly targeting elevation of privilege vulnerabilities. Satnam Narang, a Senior Staff Research Engineer at Tenable, noted that the exploitation of CLFS vulnerabilities has become a common tactic for attackers seeking to infiltrate networks.

As 2024 draws to a close, Microsoft’s proactive approach to security highlights the ongoing battle against cyber threats, underscoring the importance of timely updates for users and organizations alike. The December Patch Tuesday serves as a reminder of the ever-evolving landscape of cybersecurity and the need for vigilance in protecting sensitive data.

spot_img

Related articles

Recent articles

Experts Warn: A Major Cybersecurity Breach in Healthcare is Inevitable

Rising Cybersecurity Threats in Healthcare: A Looming Crisis The Stark Reality of Cyber Incidents Experts in the healthcare field are sounding the alarm on cybersecurity threats,...

Iranian and Egyptian Foreign Ministers Discuss Key Issues in Phone Call

Iran and Egypt Celebrate Eid al-Adha with Diplomatic Dialogue A Warm Exchange of Greetings In a significant diplomatic interaction, Iranian Foreign Minister Seyed Abbas Araghchi and...

Malicious Browser Extensions Infect 722 Users in Latin America Since Early 2025

Emerging Cyber Threat: Malicious Extension Targets Brazilian Users Cybersecurity experts have recently uncovered a concerning campaign aimed at users in Brazil, which has been ongoing...

Searchlight Cyber Aids U.S. Government in Dismantling BidenCash Dark Web Marketplace

U.S. Law Enforcement Takes Down BidenCash Dark Web Marketplace Overview of the Operation In a significant law enforcement effort announced by the U.S. Department of Justice,...