October 2024 Microsoft Patch Tuesday: CVE Updates

Published:

spot_img

Microsoft October 2024 Patch Tuesday Addresses 117 CVEs, Including Two Zero-Day Vulnerabilities

Microsoft has released the October 2024 Patch Tuesday, addressing a total of 117 Common Vulnerabilities and Exposures (CVEs). This month’s update includes three critical vulnerabilities, 113 important ones, and one moderate issue. Of particular concern are two zero-day vulnerabilities actively exploited in the wild: CVE-2024-43573 and CVE-2024-43572.

The first vulnerability, CVE-2024-43572, affects the Microsoft Management Console (MMC) and allows remote code execution through malicious Microsoft Saved Console (MSC) files. This flaw, with a CVSS score of 7.8, could compromise sensitive information stored in console windows. Microsoft has released a security update to prevent untrusted MSC files from being opened.

The second critical vulnerability, CVE-2024-43573, targets the Windows MSHTML Platform, impacting various Microsoft 365 applications, Internet Explorer 11, and Legacy Microsoft Edge browsers. With a CVSS score of 6.5, this moderate spoofing vulnerability poses risks to user security.

Security expert Satnam Narang emphasized the severity of these vulnerabilities, noting the need for immediate updates to prevent exploitation. He highlighted the increasing use of social engineering tactics to exploit these flaws.

In addition to the zero-day vulnerabilities, the Patch Tuesday update addressed other critical issues, including remote code execution and elevation of privilege vulnerabilities. Users and organizations are urged to prioritize these updates to safeguard their systems and educate employees on identifying potential threats. Stay informed and proactive to stay ahead of cyber threats in today’s digital landscape.

spot_img

Related articles

Recent articles

Ultimate Guide to Secure Vibe Coding

Understanding Vibe Coding: Navigating the New Landscape of AI-Generated Software The Rise of Vibe Coding As we move through 2025, vibe coding has emerged as a...

28 Years Later: Dark Web Hints at the Truth Behind the Rage Virus

Unveiling the Dark Side of "28 Years Later": A Mysterious Dark Web Site The buzz surrounding the upcoming film 28 Years Later has reached new...

Unlocking Human Potential: Ignite a Renaissance Together

Embracing the Future: How ServiceNow University is Pioneering a New Era of Learning In a rapidly evolving workplace shaped by technological advancements, ServiceNow has taken...

Nationwide Internet Outage Hits Iran

Iran's Internet Connectivity Takes a Severe Hit Amid Escalating Tensions Nationwide Outages Iran is currently grappling with significant internet connectivity issues as it finds itself embroiled...