Attackers finally get around to exploiting critical Microsoft bug from 2024
ID: d5142b51-3d93-5b9e-8f37-e96eb503e169
STIX ID: report--d5142b51-3d93-5b9e-8f37-e96eb503e169
Feed Name: The Register (Security)
Threat Score
**Executive summary:** CISA added a critical SQL injection vulnerability (CVE-2024-43468) in Microsoft Configuration Manager to its Known Exploited Vulnerabilities catalog after reports of active exploitation and public proof-of-concept code; Microsoft issued a patch in October 2024 and federal agencies have a March 5 remediation deadline, so affected organizations should prioritize patching immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
