Microsoft Patch Tuesday

In today’s SensCy Cyber Brief, your SensCy team reviewed Microsoft’s latest series of patches released on Tuesday, November 12, 2024. This month Microsoft fixes 4 zero-days, all actively exploited, and 89 flaws.

What is Patch Tuesday?

Patch Tuesday is Microsoft’s initiative to release new security fixes for the Windows operating system and any other Microsoft software on a monthly basis. Your SensCy team will monitor such releases and provide you with our observations and recommendations.

Why is it important?

This month’s patch Tuesday is critical because it fixes critical vulnerabilities. The SensCy team recommends Microsoft users install those patches immediately.

Below are the 4 actively exploited zero-day vulnerabilities.

CVE-2024-43451 – NTLM Hash Disclosure Spoofing Vulnerability

CVE-2024-49039 – Windows Task Scheduler Elevation of Privilege Vulnerability

CVE-2024-49040 – Microsoft Exchange Server Spoofing Vulnerability

CVE-2024-49019 – Active Directory Certificate Services Elevation of Privilege Vulnerability

In addition to the zero-day fixes, Microsoft is fixing 89 other vulnerabilities. Here is a breakdown of each vulnerability category:

  • 52 Remote Code Execution Vulnerabilities
  • 26 Elevation of Privilege Vulnerabilities
  • 4 Denial of Service Vulnerabilities
  • 3 Spoofing Vulnerabilities
  • 2 Security Feature Bypass Vulnerabilities
  • 2 Information Disclosure Vulnerabilities

For more information on vulnerabilities and the system that it affects, please refer to the full report from Microsoft linked here.