# Microsoft Patches Two Exploited Zero-Days

Published: 2024-11-12 · Severity: high
Canonical: https://vorant.io/reports/f6ae202f-91c5-594a-a8ae-a691ceab1a25/microsoft-patches-two-exploited-zero-days

> Microsoft's November 2024 Patch Tuesday fixes actively exploited flaws CVE-2024-43451 and CVE-2024-49039; IPA urges immediate patching.

Japan's IPA issued an alert regarding Microsoft's November 2024 monthly security update, which addresses multiple vulnerabilities across Microsoft products. Exploitation of these flaws could cause application crashes or allow attackers to take control of affected systems.

Of particular concern are two vulnerabilities, CVE-2024-43451 and CVE-2024-49039, which Microsoft has confirmed are being actively exploited in the wild. IPA warns that damage from these exploits could expand and urges users and organizations to apply the security updates immediately via Windows Update or through managed patch deployment processes.

## Mentioned in this report

- Vulnerabilities: CVE-2024-43451 (KEV), CVE-2024-49039 (KEV)

Source reporting: https://www.ipa.go.jp/security/security-alert/2024/1113-ms.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/f6ae202f-91c5-594a-a8ae-a691ceab1a25/microsoft-patches-two-exploited-zero-days.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
