Breaking
December 12, 2024

Microsoft fixes zero-day security flaw in latest Windows update | usagoldmines.com

Yesterday was the last Patch Tuesday of 2024, and with it Microsoft has provided a number of security updates, eliminating 71 security vulnerabilities across various Microsoft apps and services.

Microsoft categorizes 16 of these vulnerabilities as “critical” and classifies all but one of the remaining issues as “high risk.” According to the company, one of those Windows security flaws is already being exploited in the wild, so it’s crucial to patch ASAP.

With 1,020 security vulnerabilities patched throughout 2024, this has been the second worst year for Microsoft as far as sheer number of security issues. It was only surpassed once, in 2020, which saw 1,250 security vulnerabilities across the year.

Microsoft offers sparse details on these vulnerabilities in its Security Update Guide. Dustin Childs breaks down Patch Tuesday in a much clearer way on the Trend Micro ZDI blog, always with an eye for admins who manage corporate networks.

Windows security flaws patched

A large proportion of the vulnerabilities — 59 this time around — are spread across the various Windows versions (10, 11, and Server) for which Microsoft still offers security updates.

Get Windows 11 Pro for cheap

Windows 11 Pro

Windows 11 Pro

Although Windows 7 and 8.1 are no longer mentioned in security reports, they could still be vulnerable. If your system requirements allow it, you should switch to Windows 10 22H2 or Windows 11 23H2 to continue receiving security updates. The Windows 11 24H2 update is available, but you might want to hold off until its widespread issues are fixed.

Windows under attack in the wild

According to Microsoft, there are already attacks being made on one particular security vulnerability in Windows. Known as CVE-2024-49138, this buffer overflow issue in the driver of the shared protocol file system has been identified as high risk, allowing an attacker to gain system authorization via elevation of privilege.

In combination with an RCE (Remote Code Execution) security vulnerability, an attacker could gain full control of the Windows system and cause major damage. Such combinations are often seen in ransomware attacks, which are still on the rise today.

Tip: Not only should you be diligently keeping your operating system up to date, but you should also be protecting your PC with reputable antivirus software and VPN software. Check out our top picks for the best Windows antivirus suites and best VPN services.

Other critical Windows security flaws

Microsoft categorizes a total of 16 RCE vulnerabilities in Windows as critical, with the Remote Desktop service alone accounting for nine of them. Even though there are no recorded in-the-wild exploits of these vulnerabilities yet, admins should not ignore them.

The most notable is CVE-2024-49112, an RCE vulnerability in the Lightweight Directory Access Protocol (LDAP) that could allow an attacker to inject code without user login and execute it with elevated privileges. Microsoft recommends disconnecting vulnerable domain controllers from the internet as a mitigation measure against such attacks.

Microsoft also classifies the RCE vulnerability CVE-2024-49117 in Hyper-V as critical. Code from the guest system could break out and be executed on the host system. A simple user login is sufficient for the attacker.

Office security flaws patched

Microsoft has eliminated eight security vulnerabilities in its Office products, including three RCE vulnerabilities. One was in Excel, one was in Access, and the third one (known as CVE-2024-49065) can be exploited via the Outlook preview for file attachments. Fortunately, according to Microsoft, the attacker can’t access user data with this vulnerability, but can prevent its availability.

The first in a long line of AI vulnerabilities?

Microsoft

Muzic is an open-source research project by Microsoft that uses deep learning to promote the understanding and creation of music. With CVE-2024-49063, Microsoft has plugged the first of what could be many security flaws in the field of artificial intelligence.

Anyone wondering what AI vulnerabilities might look like: they look like deserialization errors. An attacker can develop malicious code that would be executed when a data stream is converted into an object.

As of December 2024, there’s no new Windows tool for removing malware. The next Patch Tuesday will be on January 14, 2025.

 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Three Great Deals on iPads That Will Arrive Before Christmas Daniel Oropeza | usagoldmines.com
Seven Custom Lists I Use on My Hearth Display (and How to Make Them) Jordan Calhoun | usagoldmines.c...
Quordle today – my hints and answers for Thursday, December 12 (game #1053) | usagoldmines.com
NYT Strands today — my hints, answers and spangram for Thursday, December 12 (game #284) | usagoldm...
NYT Connections today — my hints and answers for Thursday, December 12 (game #550) | usagoldmines.c...
ChatGPT and Sora are down – here’s what you need to know about OpenAI's outage jacob.krol@futurenet....
Best PC computer holiday deals: Top picks from desktops to all-in-ones | usagoldmines.com
This Is The Ultimate Mouse Customization Tool for Mac Justin Pot | usagoldmines.com
The Best Stretches for a Stiff Lower Back Beth Skwarecki | usagoldmines.com
Apple Shares Ad Highlighting Genmoji in iOS 18.2 Juli Clover | usagoldmines.com
Everything You Need to Know About Apple Intelligence Juli Clover | usagoldmines.com
The Refurbished Steam Deck OLED Is a Stupid Good Deal Michelle Ehrhardt | usagoldmines.com
iOS 18.2 Features: Everything New in iOS 18.2 Juli Clover | usagoldmines.com
AMD VM security tools can be bypassed, letting hackers infilitrate your devices, experts warn | usa...
Russia takes unusual route to hack Starlink-connected devices in Ukraine Dan Goodin | usagoldmines.c...
Google Adds Two Features to Android to Fight Unwanted Bluetooth Tracking Kellen | usagoldmines.com
Six Services You Can Hire to Make Moving Day Less Horrible Jeff Somers | usagoldmines.com
'Chaat' Is the Cookbook to Warm Your Winter Bones Allie Chanthorn Reinmann | usagoldmines.com
The US energy sector is being put at risk by critical third-party vulnerabilities udinmwenefosa@gmai...
The Raspberry Pi 500 is a state-of-the-art keyboard PC...just like the Tandy 1000 in the 1980s allis...
Your next favorite Christmas song might've been recorded on an iPhone jacob.krol@futurenet.com (Jaco...
Photobucket opted inactive users into privacy nightmare, lawsuit says Ashley Belanger | usagoldmines...
Errant reference in macOS 15.2 seems to confirm M4 MacBook Airs for 2025 Andrew Cunningham | usagold...
Meet TechHive, the new PCWorld home for smart home tech | usagoldmines.com
All the Winter Cleaning and Organization Tasks You Should Tackle Before the New Year Lindsey Ellefso...
Google’s Gemini 2.0 Is All About Efficiency Jake Peterson | usagoldmines.com
iOS 18.2 Brings Layered Voice Memo Recordings to iPhone 16 Pro Juli Clover | usagoldmines.com
Facebook, WhatsApp, Instagram, and Threads were down - here's what you need to know lance.ulanoff@fu...
TCL TVs will use films made with generative AI to push targeted ads Scharon Harding | usagoldmines.c...
Best laptops 2024: Premium, budget, gaming, 2-in-1s, and more | usagoldmines.com
Best VPN for streaming Netflix 2024: Watch from wherever you are | usagoldmines.com
What's New on Netflix in January 2025 Emily Long | usagoldmines.com
These Apple Intelligence Features Aren't Coming Until 2025 Juli Clover | usagoldmines.com
Google’s ‘Deep Research’ AI can write a college-level paper in minutes | usagoldmines.com
Microsoft tests compact, native version of Windows Copilot app | usagoldmines.com
The Best New iOS Features for People Who Hate AI Pranay Parab | usagoldmines.com
macOS Sequoia 15.2 Confirms New M4 MacBook Air Models Are Coming Juli Clover | usagoldmines.com
This NAS drive takes up to 12 SSDs and looks like a PS4 gaming console; but Asustor Flashstor Gen 2 ...
You can now buy a new car on Amazon – as long as it's a Hyundai | usagoldmines.com
Should you ditch unencrypted messaging apps? Here's what the experts say about the FBI's warning | ...
Google goes “agentic” with Gemini 2.0’s ambitious AI agent features Benj Edwards | usagoldmines.com
Complete Pixel 9a Spec Sheet Details Solid $499 Option Tim | usagoldmines.com
Gemini 2.0 Wants to Help You Dominate Video Games or Look Up Tips in Real-Time Kellen | usagoldmines...
21 of the Best Christmas Horror Movies Ross Johnson | usagoldmines.com
Apple Releases watchOS 11.2 Juli Clover | usagoldmines.com
Apple Releases tvOS 18.2 With Snoopy Screen Savers and Projector Support Juli Clover | usagoldmines....
Apple Releases visionOS 2.2 With Ultrawide Mac Virtual Display Juli Clover | usagoldmines.com
Apple Releases HomePod Software 18.2 With Natural Language Search for Apple Music Juli Clover | usag...
Apple Releases macOS Sequoia 15.2 With New Apple Intelligence Features Juli Clover | usagoldmines.co...
Apple Releases iOS 18.2 and iPadOS 18.2 With Genmoji, Image Playground, Siri ChatGPT and More Juli C...
Are Apple Watches unstylish? This viral couple who banned them from their wedding seem to think so m...
Firefox is ending Do Not Track, but there are better ways to protect your privacy – here's what I re...
Gemini 2.0 doubles the speed of the AI assistant –and could supercharge search erichs211@gmail.com (...
iOS 18: new features, compatible devices, and everything you need to know axel.metz@futurenet.com (A...
That's my weekend sorted –Resident Evil 2 arrives early on iPhone, iPad and Mac with a huge discount...
NASA believes it understands why Ingenuity crashed on Mars Eric Berger | usagoldmines.com
Reminder: Donate to win swag in our annual Charity Drive sweepstakes Kyle Orland | usagoldmines.com
iOS 18.2, macOS 15.2 updates arrive today with image and emoji generation Andrew Cunningham | usagol...
Get this 256GB Samsung Pro Plus microSD for just $20 right now | usagoldmines.com
The FBI says you should use encrypted messaging. But do you need to? | usagoldmines.com
Today’s best laptop deals: Save big on work, school, home use, and gaming | usagoldmines.com
Tapo’s in-wall smart outlet packs Matter, tracks your power usage | usagoldmines.com
This retro monitor looks like it fell off the OG Enterprise | usagoldmines.com
Viofo A329 dash cam review: Hyper 4K detail at 60fps | usagoldmines.com
Cyberpunk 2077 celebrates its 4th anniversary with a fresh, new update | usagoldmines.com
FCC threatens to block spammy VOIP services | usagoldmines.com
Asus’ portable laptop monitor is 36% off, down to its best-ever price | usagoldmines.com
FTC pays Fortnite players $72 million after fining Epic’s unlawful actions | usagoldmines.com
Google unveils ‘Willow’ quantum chip that smashes all modern records | usagoldmines.com
This Ryzen 9 mini PC with 24GB of RAM is only $349 right now | usagoldmines.com
Google Launches Gemini 2.0, Shows Off More Project Astra Assistant With Glasses Kellen | usagoldmine...
Four Ways to Keep Your Houseplants Happy in Winter Amanda Blum | usagoldmines.com
iOS 18.2 Is Here With New Apple Intelligence Features Jake Peterson | usagoldmines.com
This Tool Can Create Captions for Any Audio on Your Android David Nield | usagoldmines.com
Apple Vision Pro Named 2024 'Innovation of the Year' Hartley Charlton | usagoldmines.com
Apple Intelligence Officially Launching in the UK, Canada, and Four More Countries Today Joe Rossign...
Microsoft says Russia is hacking Ukrainian military tech by stealing points of entry from third-part...
Security flaw in top WordPress plugin could allow for Stripe refunds on millions of sites | usagold...
I never knew I wanted a stop-motion animated Pokemon TV show from Wallace and Gromit's creators, but...
Salt Typhoon hack – US Senator presents new bill to beef up telecoms' security chiara.castro@futuren...
You'll be able to stream the Oscars live on Hulu for the first time ever | usagoldmines.com
New congressional report: “COVID-19 most likely emerged from a laboratory” John Timmer | usagoldmine...
Report: Google told FTC Microsoft’s OpenAI deal is killing AI competition Ashley Belanger | usagoldm...
The Out-of-Touch Adults' Guide to Kid Culture: The CEO Killer and Hawk Tuah Girl Stephen Johnson | u...
The Newest Amazon Echo Dot Is at Its Lowest Price Ever Right Now Pradershika Sharma | usagoldmines.c...
Cloud-Based M4 and M4 Pro Mac Mini Models Now Available Hartley Charlton | usagoldmines.com
'M4 Extreme' Chip Unlikely After Apple 'Cancels' High-Performance Chip Joe Rossignol | usagoldmines....
Boya launches the world's smallest and lightest wireless mic, and it's super cheap | usagoldmines.c...
Google wants the FTC to stop exclusive Microsoft cloud deal with OpenAI | usagoldmines.com
My favorite Bluetooth party speaker is back, and this time there's a karaoke function becky.scarrott...
Wonder Woman game - everything we know so far catbussell@gmail.com (Cat Bussell) | usagoldmines.com
The FBI says you should use encrypted messaging. But do you need to? | usagoldmines.com
My Favorite Food Gifts (That Aren’t Kitchen Tools) Allie Chanthorn Reinmann | usagoldmines.com
Beats Launches iPhone 16 Cases in New Sunrise Pink and Twilight Blue Colors Eric Slivka | usagoldmin...
Apple Intelligence Servers Expected to Get All-New, Turbocharged Chip Joe Rossignol | usagoldmines.c...
Apple Watch Series 10 Available for Black Friday Prices and Christmas Delivery on Amazon Mitchel Bro...
These are the best Chrome Extensions of 2024 – according to Google hamish.hector@futurenet.com (Hami...
Ivanti warns it has found another major security flaw in its systems | usagoldmines.com
Asus beware, you have new competition - the MSI Claw 8 AI+ performs 20% better than the ROG Ally X a...
Cristiano Ronaldo unveils high-tech fitness recovery line, including $5,700 cryotherapy boots stephe...

Leave a Reply