logo

Microsoft Discloses 4 Zero-Days in September Update

ID: 0ebbe968-445b-540e-aef0-2304812f6bbe

STIX ID: report--0ebbe968-445b-540e-aef0-2304812f6bbe

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-09-10

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Microsoft's September security update addresses 79 vulnerabilities, including multiple zero-day flaws—two security-bypass bugs (affecting Publisher and Windows Mark of the Web), an elevation-of-privilege in Windows Installer (CVE-2024-38014), and a high-severity RCE in Windows Update (CVE-2024-43491) that reintroduced previously mitigated issues. Several of these are confirmed to be actively exploited, and administrators are advised to prioritize patches (including servicing stack and security updates KB5043936 and KB5043083) and urgently remediate the SharePoint RCE (CVE-2024-38018) which has no known mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.