2024-10-11
Microsoft Patch Tuesday
Microsoft's Patch Tuesday for October 2024 includes fixes for nearly 120 security issues, including at least two that are being actively exploited. One of the already-exploited vulnerabilities is a high-severity improper neutralization issue in Microsoft Management Console that can be exploited to achieve remote code execution. The second is a moderate severity improper input neutralization vulnerability in Windows MSHTML Platform that could lead to spoofing.
Editor's Note
Microsoft also released patches for Office, Azure, .Net, OpenSSH for Windows, Power BI, Windows Hyper-V, Mobile Broadband and Visual Studio. In addition to Microsoft's updates, make sure to also deploy the updates to Chrome/Chromium as well as the macOS 15.0.1 update which corrected the flaw affecting security tools on that platform.
Lee Neely
Read more in
Microsoft Patch Tuesday - October 2024
Krebs on Security: Patch Tuesday, October 2024 Edition
The Register: Microsoft issues 117 patches Ð some for flaws already under attack
Security Week: Microsoft Confirms Exploited Zero-Day in Windows Management Console
Microsoft: Microsoft Management Console Remote Code Execution Vulnerability | CVE-2024-43572
Microsoft: Windows MSHTML Platform Spoofing Vulnerability | CVE-2024-43573
Microsoft: October 2024 Security Updates