VORANT. Threat Intelligence Sign in Get the full feed

CVE-2024-49138 exploited in Windows patch Tuesday

high vulnerability

Microsoft's December 2024 patch Tuesday fixes an actively exploited Windows kernel driver flaw, CVE-2024-49138, that lets attackers gain control of systems.

Japan's IPA issued an advisory alongside Microsoft's December 2024 Patch Tuesday release, highlighting multiple vulnerabilities across Microsoft products that could allow application crashes or full attacker control of affected PCs. Among the disclosed flaws, CVE-2024-49138 stands out as Microsoft has confirmed it is being actively exploited in the wild, prompting IPA to urge immediate patching.

The advisory recommends organizations and individual users apply the update promptly, either through automatic Windows Update mechanisms or via coordinated deployment for managed environments. No further technical details on the exploitation method, threat actors, or targeted sectors were provided beyond the vendor's disclosure, and IPA notes it is relaying vendor-published information without additional independent analysis.

Mentioned in this report

Vulnerabilities CVE-2024-49138KEV

Source reporting: https://www.ipa.go.jp/security/security-alert/2024/1211-ms.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free