Microsoft Patches 61 Flaws, Including Two Actively Exploited Zero-Days
ID: c6485c55-b59a-5400-83f2-1b5b40e897d4
STIX ID: report--c6485c55-b59a-5400-83f2-1b5b40e897d4
Feed Name: The Hacker News
Microsoft's May 2024 Patch Tuesday fixes 61 vulnerabilities, among them two zero-days (CVE-2024-30040 — MSHTML security feature bypass; CVE-2024-30051 — DWM elevation of privilege) actively exploited in the wild and added to CISA's KEV list; the report notes these can enable arbitrary code execution and SYSTEM privileges, have been observed alongside QakBot and other malware, and that administrators should prioritize applying updates. The bulletin also addresses numerous additional RCE and privilege-escalation flaws across Windows components and Chromium-based Edge.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
