Microsoft has released its final Patch Tuesday update for 2024, addressing 72 security vulnerabilities across its software products. The update includes:
Security Fixes Breakdown:
– 17 Critical vulnerabilities
– 54 Important vulnerabilities
– 1 Moderate vulnerability
– 31 Remote code execution flaws
– 27 Privilege elevation vulnerabilities
Notable Vulnerabilities:
1. CVE-2024-49138 (CVSS: 7.8)
– Actively exploited privilege escalation flaw in Windows CLFS Driver
– Enables attackers to gain SYSTEM privileges
– Fifth CLFS vulnerability since 2022
2. CVE-2024-49112 (CVSS: 9.8)
– Highest severity issue
– Remote code execution vulnerability in Windows LDAP
– Allows unauthenticated attackers to execute arbitrary code
Additional Security Measures:
– Microsoft implementing new CLFS log file verification
– CISA mandated federal agencies to patch by December 31, 2024
– Plans to deprecate NTLM in favor of Kerberos
– Enhanced Protection for Authentication enabled by default in Exchange 2019
2024 Security Statistics:
– Total vulnerabilities patched: 1,088
– 13 Edge browser vulnerabilities addressed
– Multiple vendors including Adobe, Cisco, Google, and Intel also released security updates
The comprehensive update reflects Microsoft’s continued commitment to addressing security concerns and protecting users from emerging threats.
