Microsoft's November Patch Tuesday Tackles 90 Flaws, Including 2 Zero-Days
TL;DR Summary
Microsoft's November 2024 Patch Tuesday addresses 89 security vulnerabilities, including two zero-day exploits actively used by attackers. Key fixes include CVE-2024-49039, a privilege escalation flaw in Windows Task Scheduler, and CVE-2024-43451, a spoofing vulnerability exposing NTLMv2 hashes. Other significant patches cover vulnerabilities in Active Directory Certificate Services, Microsoft Exchange Server, Windows Kerberos, and .NET/Visual Studio. The updates also address multiple memory-related issues in SQL Server, highlighting the importance of timely patch management for system administrators.
- Microsoft Patch Tuesday, November 2024 Edition Krebs on Security
- Microsoft Fixes 90 New Flaws, Including Actively Exploited NTLM and Task Scheduler Bugs The Hacker News
- 2 Zero-Day Bugs in Microsoft's Nov. Update Under Active Exploit Dark Reading
- Windows 11 KB5046617 and KB5046633 cumulative updates released BleepingComputer
- Patch Tuesday: Critical Flaws in Adobe Commerce, Photoshop, InDesign, Illustrator SecurityWeek
Reading Insights
Total Reads
0
Unique Readers
12
Time Saved
2 min
vs 3 min read
Condensed
85%
514 → 75 words
Want the full story? Read the original article
Read on Krebs on Security