Microsoft addressed 74 Common Vulnerabilities and Exposures (CVE’s) this month, 1 which was marked as zero-day vulnerability. The most critical Common Vulnerabilities and Exposures (CVE’s) are noted below:
Microsoft Vulnerabilities:
Windows Zero-Days:
- CVE-2024-49138 – Windows Common Log File System Driver Elevation of Privilege Vulnerability
- Publicly disclosed vulnerability and actively exploited in the wild.
Other Critical CVE’s:
- CVE-2024-49112 / 49127 – Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
- CVE-2024-49124 – Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability
- CVE-2024-49118 / 49122 – Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- CVE-2024-49117 – Windows Hyper-V Remote Code Execution Vulnerability
- CVE-2024-49126 – Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability
- Windows Remote Desktop Services Remote Code Execution Vulnerability:
3rd Party Critical CVE’s:
Adobe Products:
- Adobe released 16 patches covering 167 CVE’s for Adobe Acrobat and Reader, After Effects, Animate, Bridge, Connect, Experience Manager, FrameMaker, Illustrator, Media Encoder, PDFL Software Development Kit (SDK), Photoshop, Premiere Pro, Substance 3D Modeler, Substance 3D Painter and Substance 3D Sampler. Most noted ones are included below:
Cisco:
Firefox:
Google Chrome:
- Versions 131.0.6778.139/.140 were released for Windows & Apple and version 131.0.6778.139 for Linux on November 12th .
- This update includes 3 Security Fixes.
- Chrome Release: December 10th 2024
SAP:
About FortressSRM Cyber Hygiene Offering:
Software vulnerabilities are one of the top cyber-attack vectors and one in three breaches are the result of vulnerabilities that were known about and should have been already patched.
Keeping operating systems and application software patched and secure is time consuming and tedious – an internal IT resource nightmare. Fortress SRM’s Guardian Managed Patching with Monitoring Service delivers automated, high-efficacy (97%+) updates to Microsoft and over 80 third-party software, ensuring efficient patch deployment to every device, whether on or off network. This includes the deployment of critical updates, security updates, feature updates, operating system upgrades, key Windows security setting and configurations.
The Fortress SRM real-time reporting console includes current patch levels of devices and gives the Client total visibility into what patch related activities have been performed, while real-time patch monitoring provides deep insight into approved, unapproved, pending, and failed patching efforts.
Ready to start the Cyber Hygiene journey? Contact us at: Contact Us | Fortress Security Risk Management (fortresssrm.com)