Microsoft Patches Two Exploited Zero-Days
Microsoft's November 2024 Patch Tuesday fixes actively exploited flaws CVE-2024-43451 and CVE-2024-49039; IPA urges immediate patching.
Japan's IPA issued an alert regarding Microsoft's November 2024 monthly security update, which addresses multiple vulnerabilities across Microsoft products. Exploitation of these flaws could cause application crashes or allow attackers to take control of affected systems.
Of particular concern are two vulnerabilities, CVE-2024-43451 and CVE-2024-49039, which Microsoft has confirmed are being actively exploited in the wild. IPA warns that damage from these exploits could expand and urges users and organizations to apply the security updates immediately via Windows Update or through managed patch deployment processes.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/security/security-alert/2024/1113-ms.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free