logo

October 2024 Patch Tuesday: Two Zero-Days and Three Critical Vulnerabilities Amid 118 CVEs

ID: 0128f821-1f60-5fca-a777-059c34a8c6a4

STIX ID: report--0128f821-1f60-5fca-a777-059c34a8c6a4

Feed Name: Crowdstrike Blog

Threat Score
88/100

Date Published: 2024-10-08

Date Updated: 2026-04-27

Author: Falcon Exposure Management Team

...
...

This advisory summarizes Microsoft patches for multiple vulnerabilities: two actively exploited zero-days (Microsoft Management Console CVE-2024-43572 and MSHTML CVE-2024-43573) and several critical RCE flaws affecting Configuration Manager (CVE-2024-43468), a Visual Studio Code Arduino extension (CVE-2024-43488), and Remote Desktop Protocol Server (CVE-2024-43582). With CVSS scores up to 9.8 and one RDP bug flagged as potentially wormable, the report urges immediate application of updates and mitigations via Microsoft's fixes and CrowdStrike Falcon tooling.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.