VORANT. Threat Intelligence Sign in Get the full feed

Microsoft Patches Two Exploited Zero-Days

elevated vulnerability

Microsoft's October 2024 patch Tuesday fixes two actively exploited flaws, CVE-2024-43572 and CVE-2024-43573; IPA urges immediate updates.

Japan's IPA issued an alert on October 9, 2024 covering Microsoft's monthly security update release, which addresses multiple vulnerabilities across Microsoft products. Among these, Microsoft has confirmed that two vulnerabilities—CVE-2024-43572 and CVE-2024-43573—are being actively exploited in the wild.

Successful exploitation of the patched vulnerabilities could allow application crashes or full attacker control of affected systems. IPA warns that exploitation of the two confirmed vulnerabilities may expand, and urges both individual users and organizations managing update deployments to apply the patches immediately via Windows Update or their update management processes.

Mentioned in this report

Vulnerabilities CVE-2024-43572KEVCVE-2024-43573KEV

Source reporting: https://www.ipa.go.jp/security/security-alert/2024/1009-ms.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free