Critical Windows Flaw Under Attack: Microsoft Rushes Fix in 72-Bug Security Update


Microsoft’s December 2024 Patch Tuesday: Critical Security Update Overview

Microsoft has released its final Patch Tuesday update for 2024, addressing 72 security vulnerabilities across its software products. The update includes:

Security Fixes Breakdown:
– 17 Critical vulnerabilities
– 54 Important vulnerabilities
– 1 Moderate vulnerability
– 31 Remote code execution flaws
– 27 Privilege elevation vulnerabilities

Notable Vulnerabilities:

1. CVE-2024-49138 (CVSS: 7.8)
– Actively exploited privilege escalation flaw in Windows CLFS Driver
– Enables attackers to gain SYSTEM privileges
– Fifth CLFS vulnerability since 2022

2. CVE-2024-49112 (CVSS: 9.8)
– Highest severity issue
– Remote code execution vulnerability in Windows LDAP
– Allows unauthenticated attackers to execute arbitrary code

Additional Security Measures:
– Microsoft implementing new CLFS log file verification
– CISA mandated federal agencies to patch by December 31, 2024
– Plans to deprecate NTLM in favor of Kerberos
– Enhanced Protection for Authentication enabled by default in Exchange 2019

2024 Security Statistics:
– Total vulnerabilities patched: 1,088
– 13 Edge browser vulnerabilities addressed
– Multiple vendors including Adobe, Cisco, Google, and Intel also released security updates

The comprehensive update reflects Microsoft’s continued commitment to addressing security concerns and protecting users from emerging threats.

Share This Article