Microsoft December Patch Tuesday 2024: 71 Vulnerabilities Addressed, Including Critical Zero-Day Flaws
ID: e477ed63-4123-5bb5-93e1-8acc4f89b985
STIX ID: report--e477ed63-4123-5bb5-93e1-8acc4f89b985
Feed Name: The Cyber Express
Threat Score
Microsoft’s December 2024 Patch Tuesday addresses 71 new issues as part of a year that saw 1,009 CVEs patched; the bulletin highlights CVE-2024-49138 (a CLFS heap-based buffer overflow elevation-of-privilege zero-day actively exploited in the wild, CVSSv3 7.8), critical remote code execution flaws in SharePoint and MSMQ (CVSS up to 8.1), and notes that ransomware operators have increasingly leveraged CLFS vulnerabilities to escalate privileges and move laterally.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
