Fat Patch Tuesday, February 2024 Edition
ID: c170d60d-db0a-535a-9654-799e04431940
STIX ID: report--c170d60d-db0a-535a-9654-799e04431940
Feed Name: Krebs on Security
Microsoft released patches for more than 70 vulnerabilities, including two zero-days being actively exploited: CVE-2024-21412 (an Internet Shortcut handling bypass linked to the APT "Water Hydra" that uses a malicious .msi to deploy a RAT) and CVE-2024-21351 (a Windows SmartScreen bypass); the bulletin also calls out Exchange elevation-of-privilege CVE-2024-21410 which can leak NTLM hashes and a critical Office RCE CVE-2024-21413 exploitable via Outlook's Preview pane, and urges administrators to apply required updates and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
