# Microsoft Patch Tuesday: Two zero-days exploited

Published: 2024-11-12 · Severity: high
Canonical: https://vorant.io/reports/f6ae202f-91c5-594a-a8ae-a691ceab1a25/microsoft-patch-tuesday-two-zero-days-exploited

> Microsoft's November 2024 Patch Tuesday addresses multiple vulnerabilities, including CVE-2024-43451 and CVE-2024-49039, both actively exploited in the wild.

Japan's Information-technology Promotion Agency (IPA) has issued an advisory following Microsoft's November 13, 2024 Patch Tuesday release. The update addresses multiple security vulnerabilities in Microsoft products that could allow attackers to crash applications or gain control of affected systems.

Two vulnerabilities, CVE-2024-43451 and CVE-2024-49039, are confirmed by Microsoft to be under active exploitation. The IPA warns that the threat may expand and urges organizations to apply the security updates immediately. For most users, Windows Update will automatically download and install the patches, though system restarts may be required.

Organizations managing their own update deployments should refer to Microsoft's monthly security bulletin and prioritize rapid rollout of these patches across their environments.

## Mentioned in this report

- Vulnerabilities: CVE-2024-43451 (KEV), CVE-2024-49039 (KEV)

Source reporting: https://www.ipa.go.jp/security/security-alert/2024/1113-ms.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/f6ae202f-91c5-594a-a8ae-a691ceab1a25/microsoft-patch-tuesday-two-zero-days-exploited.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
