In its final Patch Tuesday of 2024, Microsoft released security updates to address 71 vulnerabilities, including an actively exploited zero-day flaw.
The latest security update rollout also includes fixes for 16 flaws deemed critical, predominantly remote code execution (RCE) vulnerabilities.
As BleepingComputer reported, the shortcomings addressed in Microsoft’s latest release span a broad range of categories, including:
The list excludes two vulnerabilities in Microsoft Edge that were patched in earlier updates on December 5 and 6.
The most notable vulnerability, CVE-2024-49138, is a critical elevation of privilege flaw impacting Windows’ Common Log File System (CLFS) Driver.
This flaw has been exploited in attacks in the wild, allowing attackers to gain SYSTEM-level privileges on vulnerable Windows devices.
Among the 16 critical vulnerabilities addressed, several others stand out due to their potential impact:
Windows users and administrators should prioritize installing the latest batch of security updates to deter attacks that exploit the listed vulnerabilities.
Using a dedicated security solution like Bitdefender Ultimate Security can boost your cyber resilience. It detects and neutralizes viruses, Trojans, worms, zero-day exploits, ransomware, spyware, rootkits, and other digital threats.
Additionally, it encompasses advanced features including behavioral analysis for active apps, network threat prevention, a vulnerability assessment tool, AI-powered scam detection, web attack prevention modules and multi-layer ransomware protection.
tags
Vlad's love for technology and writing created rich soil for his interest in cybersecurity to sprout into a full-on passion. Before becoming a Security Analyst, he covered tech and security topics.
View all postsNovember 14, 2024
September 06, 2024