Only one critical vulnerability included in May’s Microsoft Patch Tuesday; One other zero-day in DWN Core
ID: 08cb6d2b-575a-5cb9-bcea-430faf2123c3
STIX ID: report--08cb6d2b-575a-5cb9-bcea-430faf2123c3
Feed Name: Cisco Talos
Microsoft’s May security update disclosed 59 CVEs—mostly “important” severity—including a critical SharePoint remote code execution (CVE-2024-30044) requiring authenticated Site Owner access and a zero-day Desktop Window Manager privilege escalation (CVE-2024-30051) that grants SYSTEM privileges and has been observed in the wild; additional issues include Windows Mobile Broadband driver RCEs requiring physical USB access and an ASP.NET DoS (CVE-2024-30046). Cisco Talos released Snort rules (IDs listed) to detect exploitation attempts and recommends customers update rule sets to protect against these vulnerabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
