October 2024 Patch Tuesday: Two Zero-Days and Three Critical Vulnerabilities Amid 118 CVEs
ID: 0128f821-1f60-5fca-a777-059c34a8c6a4
STIX ID: report--0128f821-1f60-5fca-a777-059c34a8c6a4
Feed Name: Crowdstrike Blog
This advisory summarizes Microsoft patches for multiple vulnerabilities: two actively exploited zero-days (Microsoft Management Console CVE-2024-43572 and MSHTML CVE-2024-43573) and several critical RCE flaws affecting Configuration Manager (CVE-2024-43468), a Visual Studio Code Arduino extension (CVE-2024-43488), and Remote Desktop Protocol Server (CVE-2024-43582). With CVSS scores up to 9.8 and one RDP bug flagged as potentially wormable, the report urges immediate application of updates and mitigations via Microsoft's fixes and CrowdStrike Falcon tooling.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
