Microsoft Patch Tuesday
In today’s SensCy Cyber Brief, your SensCy team reviewed Microsoft’s latest series of patches released on Tuesday, May 14, 2024. This month Microsoft fixes four zero-days and 142 flaws.
What is Patch Tuesday?
Patch Tuesday is Microsoft’s initiative to release new security fixes for the Windows operating system and any other Microsoft software on a monthly basis. Your SensCy team will monitor such releases and provide you with our observations and recommendations.
Why is it important?
This month’s patch Tuesday is critical because it fixes critical vulnerabilities. The SensCy team recommends Microsoft users install those patches immediately.
This month’s patch Tuesday fixes four zero-day vulnerability, with two being actively exploited and two publicly disclosed.
The two exploited vulnerabilities are CVE-2024-38080, a vulnerability actively exploited Hyper-V elevation of privileges vulnerability that gives attackers SYSTEM privileges. “An attacker who successfully exploited this vulnerability could gain SYSTEM privileges,” explains Microsoft. And CVE-2024-38112, an actively exploited Windows MSHTML spoofing vulnerability.
The two publicly disclosed vulnerabilities can be tracked as CVE-2024-35264 and CVE-2024-37985.
In addition to the zero-day fixes, Microsoft is fixing 142 other vulnerabilities. Here is a breakdown of each vulnerability category:
- 59 Remote Code Execution Vulnerabilities
- 26 Elevation of Privilege Vulnerabilities
- 24 Security Feature Bypass Vulnerabilities
- 17 Denial of Service Vulnerabilities
- 9 Information Disclosure Vulnerabilities
- 7 Spoofing Vulnerabilities
For more information on vulnerabilities and the system that it affects, please refer to the full report from Microsoft linked here.

