Microsoft's November Patch Tuesday Tackles 90 Flaws, Including 2 Zero-Days

1 min read
Source: Krebs on Security
TL;DR Summary

Microsoft's November 2024 Patch Tuesday addresses 89 security vulnerabilities, including two zero-day exploits actively used by attackers. Key fixes include CVE-2024-49039, a privilege escalation flaw in Windows Task Scheduler, and CVE-2024-43451, a spoofing vulnerability exposing NTLMv2 hashes. Other significant patches cover vulnerabilities in Active Directory Certificate Services, Microsoft Exchange Server, Windows Kerberos, and .NET/Visual Studio. The updates also address multiple memory-related issues in SQL Server, highlighting the importance of timely patch management for system administrators.

Share this article

Reading Insights

Total Reads

0

Unique Readers

12

Time Saved

2 min

vs 3 min read

Condensed

85%

51475 words

Want the full story? Read the original article

Read on Krebs on Security