Microsoft closes 2024 with extensive security update
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-49112 | Unauthenticated RCE in Microsoft Windows LDAP (CVE-2024-49112) CVE-2024-49112 is an integer overflow (CWE-190) in the Windows Lightweight Directory Access Protocol (LDAP) implementation that permits remote code execution. It is triggered by network traffic sent to the LDAP service, with no authentication or user interaction required (CVSS 3.1 network vector, low complexity, no privileges). A successful attacker gains arbitrary code execution in the context of the LDAP service process on the target, and on Active Directory domain controllers this typically means compromising a core infrastructure host with high confidentiality, integrity, and availability impact. All listed Windows 10 and Windows 11 client versions and Windows Server 2008 through 2022 are affected, making virtually every unpatched Windows environment — especially those running domain controllers — exposed. Per related coverage, the flaw was addressed in Microsoft's December 2024 Patch Tuesday (72 flaws fixed, four rated critical); no public proof-of-concept or confirmed in-the-wild exploitation is known for this specific RCE yet, though a related Windows LDAP flaw ('LDAPNightmare') has a public PoC that crashes LSASS and reboots domain controllers, and the ~71% EPSS score signals a high likelihood of exploitation within 30 days. Do: Apply Microsoft's December 2024 (or later) Windows security updates immediately, prioritizing domain controllers and any server with LDAP reachable from untrusted networks. Until fully patched, restrict inbound LDAP/LDAPS traffic (TCP and UDP 389 and 636) to trusted sources and monitor for LSASS crashes or restarts on domain controllers. Because fixes are version-specific cumulative updates, verify each Windows release against Microsoft's advisory to confirm the correct KB is installed. | 9.8 | 71% |
| massorder of millions of systems | ||
| CVE-2024-49138 | Local Privilege Escalation via Heap Overflow in Microsoft Windows CLFS Driver Microsoft's Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow (CWE-122) that a local attacker can trigger by submitting crafted input to the CLFS component after gaining the ability to run code on the target machine. Successful exploitation overwrites heap memory in the kernel driver and allows the attacker to escalate privileges, typically from an ordinary user account to SYSTEM-level execution. Any Microsoft Windows system is potentially affected; the CISA listing identifies only "Microsoft Windows" and does not enumerate specific versions or builds, and no CVSS score has been published yet. The flaw was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2024-12-10, confirming it is being exploited in the wild (ransomware use is unknown), and EPSS assigns a 25.4% probability of exploitation activity within 30 days (98th percentile). No public proof-of-concept is known, but the in-the-wild exploitation means defenders should treat this as an actively used privilege-escalation primitive, often chained after initial access by malware or another exploit. Do: Apply Microsoft's security update for Windows per vendor instructions, as required by the CISA KEV listing (added 2024-12-10), and verify patch compliance across Windows endpoints. Because this is a local privilege escalation, prioritize hosts where untrusted users or malware execute code, and review telemetry for local code execution followed by unexpected escalation to SYSTEM. No public PoC exists, so detection should rely on vendor advisory guidance and EDR telemetry rather than public exploit signatures. | 7.8 | 25% | KEV PoC ×2 |
| masshundreds of millions to 1 billion+ Windows installations (Windows runs on 1B+ active devices) |
Full article532 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Adobe, too.
Listen to this article
0:00
Learn more.
In its final Patch Tuesday update of 2024, Microsoft has addressed 71 new security vulnerabilities, including a zero-day flaw that is currently being actively exploited.
The zero-day vulnerability, documented as CVE-2024-49138, is a bug in the company’s Windows Common Log File System (CLFS). It poses a significant threat as it enables attackers to achieve system-level privileges via a heap-based buffer overflow, potentially allowing for ransomware attacks and other escalated cyber threats.
Detailed information about the specific extent or location of its exploitation has not been disclosed. CISA on Tuesday added the vulnerability to its Known Exploited Vulnerabilities list.
In tandem, Microsoft has urged immediate attention to another severe vulnerability, CVE-2024-49112, in the Windows Lightweight Directory Access Protocol (LDAP). The vulnerability carries a CVSS severity score of 9.8. This flaw can allow an attacker to execute remote code without authentication, posing a high risk to domain controllers central to network security structures. Microsoft’s advisory recommends urgent patching and isolation of LDAP services from untrusted networks to prevent potential exploits.
This month’s fixes highlight pressing threats within the Windows ecosystem, particularly the vulnerabilities enabling unauthorized access or remote code execution across critical services like Remote Desktop and Hyper-V. These patches underscore vulnerabilities that can readily be weaponized by cybercriminals aiming to exploit widely used enterprise components.
Also on Tuesday, Adobe issued patches addressing 167 vulnerabilities across its software suite, with significant updates in products like Adobe Experience Manager and Adobe Connect. None of Adobe’s patched vulnerabilities were known to be under active exploitation at the time of release.
Organizations are strongly encouraged to expedite these patches, given the severity scores and the additions to the KEV list.
You can view the full Microsoft list in the company’s Security Response Center.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/microsoft-patch-tuesday-december-2024/