October 2024 Microsoft Patch Tuesday: CVE Updates

Published:

spot_img

Microsoft October 2024 Patch Tuesday Addresses 117 CVEs, Including Two Zero-Day Vulnerabilities

Microsoft has released the October 2024 Patch Tuesday, addressing a total of 117 Common Vulnerabilities and Exposures (CVEs). This month’s update includes three critical vulnerabilities, 113 important ones, and one moderate issue. Of particular concern are two zero-day vulnerabilities actively exploited in the wild: CVE-2024-43573 and CVE-2024-43572.

The first vulnerability, CVE-2024-43572, affects the Microsoft Management Console (MMC) and allows remote code execution through malicious Microsoft Saved Console (MSC) files. This flaw, with a CVSS score of 7.8, could compromise sensitive information stored in console windows. Microsoft has released a security update to prevent untrusted MSC files from being opened.

The second critical vulnerability, CVE-2024-43573, targets the Windows MSHTML Platform, impacting various Microsoft 365 applications, Internet Explorer 11, and Legacy Microsoft Edge browsers. With a CVSS score of 6.5, this moderate spoofing vulnerability poses risks to user security.

Security expert Satnam Narang emphasized the severity of these vulnerabilities, noting the need for immediate updates to prevent exploitation. He highlighted the increasing use of social engineering tactics to exploit these flaws.

In addition to the zero-day vulnerabilities, the Patch Tuesday update addressed other critical issues, including remote code execution and elevation of privilege vulnerabilities. Users and organizations are urged to prioritize these updates to safeguard their systems and educate employees on identifying potential threats. Stay informed and proactive to stay ahead of cyber threats in today’s digital landscape.

spot_img

Related articles

Recent articles

Iranian and Egyptian Foreign Ministers Discuss Key Issues in Phone Call

Iran and Egypt Celebrate Eid al-Adha with Diplomatic Dialogue A Warm Exchange of Greetings In a significant diplomatic interaction, Iranian Foreign Minister Seyed Abbas Araghchi and...

Malicious Browser Extensions Infect 722 Users in Latin America Since Early 2025

Emerging Cyber Threat: Malicious Extension Targets Brazilian Users Cybersecurity experts have recently uncovered a concerning campaign aimed at users in Brazil, which has been ongoing...

Searchlight Cyber Aids U.S. Government in Dismantling BidenCash Dark Web Marketplace

U.S. Law Enforcement Takes Down BidenCash Dark Web Marketplace Overview of the Operation In a significant law enforcement effort announced by the U.S. Department of Justice,...

Report: Stolen Credentials Are the Top Entry Point for Hackers

Stolen Credentials: The Most Common Gateway for Cyber Intrusions In the realm of cybersecurity, keeping networks secure is paramount. A recent analysis by the cybersecurity...