VORANT. Threat Intelligence Sign in Get the full feed

Microsoft patches two exploited zero-days

high vulnerability

Microsoft's October 2024 patch Tuesday addresses CVE-2024-43572 and CVE-2024-43573, both confirmed exploited in the wild, enabling attackers to control systems.

Japan's IPA has issued an urgent advisory following Microsoft's October 2024 patch Tuesday release. The update addresses multiple vulnerabilities in Microsoft products, including two zero-day flaws that Microsoft confirms are being actively exploited in the wild. The exploited vulnerabilities are tracked as CVE-2024-43572 and CVE-2024-43573. Successful exploitation of these flaws could allow attackers to cause application crashes, achieve remote code execution, or gain full control of compromised systems.

IPA emphasizes the urgency of applying these security updates immediately due to confirmed exploitation and the risk of expanded targeting. Organizations are advised to deploy patches through their standard update management processes. For individual users, Windows Update typically handles security patches automatically, though system restarts may be required to complete installation.

Mentioned in this report

Vulnerabilities CVE-2024-43572KEVCVE-2024-43573KEV

Source reporting: https://www.ipa.go.jp/security/security-alert/2024/1009-ms.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free