logo

Patch Tuesday roundup for December 2024

ID: abade5c9-0b45-5ddb-82d1-01bbbee7cab7

STIX ID: report--abade5c9-0b45-5ddb-82d1-01bbbee7cab7

Feed Name: Expel Blog

Threat Score
70/100

Date Published: 2024-12-11

Date Updated: 2026-04-27

Author: Matt Jastram

...
...

December Patch Tuesday published 73 Microsoft CVEs; this report from Expel highlights a few high-risk issues—notably a CLFS heap-based privilege escalation (CVE-2024-49138) and related CVEs (CVE-2024-49088, CVE-2024-49090) added to CISA's KEV, an Edge (Chromium) spoofing vulnerability (CVE-2024-49041) and related browser fixes, and an LDAP remote code execution vulnerability (CVE-2024-49112) impacting many Windows versions—and recommends patching immediately according to Microsoft guidance to mitigate active or likely exploitation risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.