U.S. CISA provides Microsoft Home windows CLFS driver flaw to its Recognized Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Safety Company (CISA) provides Microsoft Home windows Frequent Log File System (CLFS) driver flaw to its Recognized Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Safety Company (CISA) added the Microsoft Home windows Frequent Log File System (CLFS) driver flaw CVE-2024-49138 (CVSS rating: 7.8) to its Known Exploited Vulnerabilities (KEV) catalog.
Microsoft December 2024 Patch Tuesday safety updates addressed 71 vulnerabilities together with an actively exploited zero-day, tracked as CVE-2024-49138. Microsoft didn’t disclose details about the assault exploiting this vulnerability.
An attacker can exploit this vulnerability to realize SYSTEM privileges.
“Microsoft Home windows Frequent Log File System (CLFS) driver comprises a heap-based buffer overflow vulnerability that enables an area attacker to escalate privileges.” reads the advisory.
In keeping with Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB companies have to handle the recognized vulnerabilities by the due date to guard their networks towards assaults exploiting the failings within the catalog.
Specialists additionally suggest personal organizations evaluate the Catalog and handle the vulnerabilities of their infrastructure.
CISA orders federal companies to repair this vulnerability by December 31, 2024.
Observe me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA Known Exploited Vulnerabilities catalog)
This articles is written by : Nermeen Nabil Khear Abdelmalak
All rights reserved to : USAGOLDMIES . www.usagoldmines.com
You can Enjoy surfing our website categories and read more content in many fields you may like .
Why USAGoldMines ?
USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.