Actively Exploited Zero-Day, Critical RCEs Lead Microsoft Patch Tuesday
ID: 1df23708-350a-551d-9b80-ab8cd16c2ab1
STIX ID: report--1df23708-350a-551d-9b80-ab8cd16c2ab1
Feed Name: Dark Reading
Date Published: 2024-12-10
Date Updated: 2026-04-21
Author: Tara Seals, Managing Editor, News, Dark Reading
Microsoft's December 2024 Patch Tuesday delivers 71 fixes (1,020 for the year) and calls out an actively exploited Windows CLFS zero-day allowing privilege escalation (CVE-2024-49138), a critical unauthenticated LDAP RCE that can compromise Domain Controllers (CVE-2024-49112, CVSS 9.8), Hyper-V guest-to-host/cross-VM RCE (CVE-2024-49117), and multiple high-severity Remote Desktop Service vulnerabilities; administrators are advised to prioritize immediate patching due to active exploitation and high-impact consequences.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
