# Microsoft patches two exploited zero-days

Published: 2024-10-08 · Severity: high
Canonical: https://vorant.io/reports/2fd924d8-ff63-5473-8dbb-d342ca2b753a/microsoft-patches-two-exploited-zero-days

> Microsoft's October 2024 patch Tuesday addresses CVE-2024-43572 and CVE-2024-43573, both confirmed exploited in the wild, enabling attackers to control systems.

Japan's IPA has issued an urgent advisory following Microsoft's October 2024 patch Tuesday release. The update addresses multiple vulnerabilities in Microsoft products, including two zero-day flaws that Microsoft confirms are being actively exploited in the wild. The exploited vulnerabilities are tracked as CVE-2024-43572 and CVE-2024-43573. Successful exploitation of these flaws could allow attackers to cause application crashes, achieve remote code execution, or gain full control of compromised systems.

IPA emphasizes the urgency of applying these security updates immediately due to confirmed exploitation and the risk of expanded targeting. Organizations are advised to deploy patches through their standard update management processes. For individual users, Windows Update typically handles security patches automatically, though system restarts may be required to complete installation.

## Mentioned in this report

- Vulnerabilities: CVE-2024-43572 (KEV), CVE-2024-43573 (KEV)

Source reporting: https://www.ipa.go.jp/security/security-alert/2024/1009-ms.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/2fd924d8-ff63-5473-8dbb-d342ca2b753a/microsoft-patches-two-exploited-zero-days.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
