logo

Microsoft December Patch Tuesday 2024: 71 Vulnerabilities Addressed, Including Critical Zero-Day Flaws

ID: e477ed63-4123-5bb5-93e1-8acc4f89b985

STIX ID: report--e477ed63-4123-5bb5-93e1-8acc4f89b985

Feed Name: The Cyber Express

Threat Score
88/100

Date Published: 2024-12-11

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

Microsoft’s December 2024 Patch Tuesday addresses 71 new issues as part of a year that saw 1,009 CVEs patched; the bulletin highlights CVE-2024-49138 (a CLFS heap-based buffer overflow elevation-of-privilege zero-day actively exploited in the wild, CVSSv3 7.8), critical remote code execution flaws in SharePoint and MSMQ (CVSS up to 8.1), and notes that ransomware operators have increasingly leveraged CLFS vulnerabilities to escalate privileges and move laterally.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.