The February 2024 Security Update Review
ID: 0692142b-d648-5660-a610-493bda301696
STIX ID: report--0692142b-d648-5660-a610-493bda301696
Feed Name: Zero Day Initiative (ZDI) Blog
**February 2024 patch summary:** Adobe released six updates addressing 29 CVEs across Acrobat/Reader, Commerce, Substance 3D products, FrameMaker Publishing Server, and Audition (none reported as publicly exploited at release). Microsoft released patches covering 72 new Windows/Office/Azure/etc. CVEs (78 total including Chromium fixes), with several high-severity fixes and multiple actively exploited vulnerabilities called out—most notably CVE-2024-21412 (Internet Shortcut files SFB), CVE-2024-21351 (SmartScreen bypass), CVE-2024-21410 (Exchange privilege escalation, CVSS 9.8, actively exploited), and CVE-2024-21413 (Outlook RCE/Protected View bypass). Administrators are advised to prioritize Exchange/Outlook/SmartScreen-related updates and deploy patches quickly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
