logo

2 Zero-Day Bugs in Microsoft's Nov. Update Under Active Exploit

ID: 6a6b0efb-ad0c-5c84-bcca-a3a7ef8c387b

STIX ID: report--6a6b0efb-ad0c-5c84-bcca-a3a7ef8c387b

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2024-11-12

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Microsoft's November Patch Tuesday fixed 89 CVEs including four zero-days—two actively exploited (NTLMv2 hash disclosure CVE-2024-43451 and Task Scheduler privilege escalation CVE-2024-49039) and two publicly disclosed but not yet exploited (AD CS elevation CVE-2024-49019 and Exchange spoofing CVE-2024-49040); the update also contains a large set of remote code execution vulnerabilities (52 RCEs) and several near-critical flaws (notably Kerberos CVE-2024-43639, CVSS 9.8), so organizations are urged to prioritize patching and secure certificate templates and Exchange headers where applicable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.