Microsoft's November 2024 Updates Address Critical Zero-Day Exploits

TL;DR Summary
Microsoft has released patches for over 90 vulnerabilities, including two critical zero-day exploits in the Windows Task Scheduler and NTLMv2 hash disclosure. The Task Scheduler flaw, CVE-2024-49039, allows privilege escalation and has a CVSS score of 8.8, while the NTLMv2 issue, CVE-2024-43451, can be triggered with minimal user interaction. Additionally, critical vulnerabilities in .NET, Visual Studio, and Windows Kerberos were addressed, with some carrying a CVSS score of 9.8. These updates coincide with Adobe's security fixes for critical flaws in its software products.
- Microsoft Confirms Zero-Day Exploitation of Task Scheduler Flaw SecurityWeek
- Microsoft Patch Tuesday, November 2024 Edition Krebs on Security
- 2 Zero-Day Bugs in Microsoft's Nov. Update Under Active Exploit Dark Reading
- Windows 11 KB5046617 and KB5046633 cumulative updates released BleepingComputer
- The November 2024 Security Update Review Zero Day Initiative
Reading Insights
Total Reads
0
Unique Readers
11
Time Saved
2 min
vs 3 min read
Condensed
85%
565 → 83 words
Want the full story? Read the original article
Read on SecurityWeek