# Microsoft December 2024 patch cycle addresses multiple vulnerabilities including…

Published: 2024-12-10 · Severity: critical
Canonical: https://vorant.io/reports/befa59fa-eef4-43d6-9f72-97493d9b71cd/microsoft-december-2024-patch-cycle-addresses-multiple-vulnerabilities-including

> Microsoft December 2024 patch cycle addresses multiple vulnerabilities including CVE-2024-49138, which is actively exploited in the wild.

Japan's Information-technology Promotion Agency (IPA) has issued an advisory regarding Microsoft's December 2024 security updates released on December 11, 2024 (JST). The update cycle addresses multiple vulnerabilities affecting Microsoft products that, if exploited, could lead to application crashes, remote code execution, or complete system compromise by attackers.

Among the patched vulnerabilities, Microsoft has confirmed active exploitation of CVE-2024-49138. IPA emphasizes the critical nature of this vulnerability and warns that attack activity may escalate, urging organizations and users to apply patches immediately. The advisory notes that Windows Update typically handles security patches automatically, but organizations with managed update processes should expedite deployment.

The IPA recommends that all users verify patch installation through Windows Update and notes that system restarts may be required to complete the update process. Organizations are directed to consult Microsoft's official security bulletin for detailed information on the December 2024 patch cycle.

## Mentioned in this report

- Vulnerabilities: CVE-2024-49138 (KEV)

Source reporting: https://www.ipa.go.jp/security/security-alert/2024/1211-ms.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/befa59fa-eef4-43d6-9f72-97493d9b71cd/microsoft-december-2024-patch-cycle-addresses-multiple-vulnerabilities-including.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
