logo

Microsoft Fixes 149 Flaws in Huge April Patch Release, Zero-Days Included

ID: 0048807e-c0ea-590e-ba77-d7009720f001

STIX ID: report--0048807e-c0ea-590e-ba77-d7009720f001

Feed Name: The Hacker News

Threat Score
76/100

Date Published: 2024-04-10

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Microsoft's April 2024 security updates address 149 vulnerabilities, including two known to be exploited in the wild (CVE-2024-26234 proxy driver spoofing and CVE-2024-29988 SmartScreen bypass). Sophos identified a WHCP-signed malicious executable ('Catalog.exe') containing a 3proxy backdoor linked to software from Hainan YouHu/LaiXi with variants traced back to January 2023, and Microsoft has revoked the related files; the bulletin also calls out a critical AKS confidential container elevation (CVE-2024-29990), multiple Secure Boot bypasses, and SharePoint exfiltration techniques, recommending timely patching and monitoring of audit logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.