logo

Actively Exploited Zero-Day, Critical RCEs Lead Microsoft Patch Tuesday

ID: 1df23708-350a-551d-9b80-ab8cd16c2ab1

STIX ID: report--1df23708-350a-551d-9b80-ab8cd16c2ab1

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2024-12-10

Date Updated: 2026-04-21

Author: Tara Seals, Managing Editor, News, Dark Reading

...
...

Microsoft's December 2024 Patch Tuesday delivers 71 fixes (1,020 for the year) and calls out an actively exploited Windows CLFS zero-day allowing privilege escalation (CVE-2024-49138), a critical unauthenticated LDAP RCE that can compromise Domain Controllers (CVE-2024-49112, CVSS 9.8), Hyper-V guest-to-host/cross-VM RCE (CVE-2024-49117), and multiple high-severity Remote Desktop Service vulnerabilities; administrators are advised to prioritize immediate patching due to active exploitation and high-impact consequences.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.