2 Zero-Day Bugs in Microsoft's Nov. Update Under Active Exploit
ID: 6a6b0efb-ad0c-5c84-bcca-a3a7ef8c387b
STIX ID: report--6a6b0efb-ad0c-5c84-bcca-a3a7ef8c387b
Feed Name: Dark Reading
Microsoft's November Patch Tuesday fixed 89 CVEs including four zero-days—two actively exploited (NTLMv2 hash disclosure CVE-2024-43451 and Task Scheduler privilege escalation CVE-2024-49039) and two publicly disclosed but not yet exploited (AD CS elevation CVE-2024-49019 and Exchange spoofing CVE-2024-49040); the update also contains a large set of remote code execution vulnerabilities (52 RCEs) and several near-critical flaws (notably Kerberos CVE-2024-43639, CVSS 9.8), so organizations are urged to prioritize patching and secure certificate templates and Exchange headers where applicable.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
