logo

The December 2024 Security Update Review

ID: 5a5232fc-364b-5f9f-917d-b084cc1f1261

STIX ID: report--5a5232fc-364b-5f9f-917d-b084cc1f1261

Feed Name: Zero Day Initiative (ZDI) Blog

Threat Score
70/100

Date Published: 2024-12-10

Date Updated: 2026-05-01

Author: Dustin Childs

...
...

Adobe and Microsoft published December 2024 security bulletins: Adobe released 16 updates fixing 167 CVEs across many products (Experience Manager accounting for 91 CVEs, mostly XSS, and Animate addressing 13 critical code-execution bugs), while Microsoft released 71 CVEs (72 including third-party) spanning Windows, Office, Hyper-V, and other components. Notable Microsoft issues include an actively exploited Windows CLFS elevation-of-privilege (CVE-2024-49138) and a 9.8 CVSS unauthenticated LDAP remote code execution that can affect Domain Controllers (CVE-2024-49112); administrators are advised to test and deploy patches promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.