logo

Attackers finally get around to exploiting critical Microsoft bug from 2024

ID: d5142b51-3d93-5b9e-8f37-e96eb503e169

STIX ID: report--d5142b51-3d93-5b9e-8f37-e96eb503e169

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2026-02-13

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

**Executive summary:** CISA added a critical SQL injection vulnerability (CVE-2024-43468) in Microsoft Configuration Manager to its Known Exploited Vulnerabilities catalog after reports of active exploitation and public proof-of-concept code; Microsoft issued a patch in October 2024 and federal agencies have a March 5 remediation deadline, so affected organizations should prioritize patching immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.