logo

The November 2024 Security Update Review

ID: aeca38e1-c67f-5a56-bf4e-8bd5c6fa0abb

STIX ID: report--aeca38e1-c67f-5a56-bf4e-8bd5c6fa0abb

Feed Name: Zero Day Initiative (ZDI) Blog

Threat Score
70/100

Date Published: 2024-11-12

Date Updated: 2026-05-01

Author: Dustin Childs

...
...

This Patch Tuesday analysis reviews Microsoft’s November security fixes, calling out multiple critical and high-severity vulnerabilities — including guest-to-host Hyper-V escapes leading to SYSTEM execution, an SMBv3-over-QUIC RCE, an Azure CycleCloud CVSS 9.9 privilege escalation to root, various SQL Server and Telephony RCEs, and several privilege escalation and security feature bypass issues — and urges administrators to apply updates and any required third-party fixes while noting limited public exploitation detail.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.