Technology NewsTechnology NewsTechnology News
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Reading: Microsoft Patches Critical Zero-Day Vulnerabilities
Share
Font ResizerAa
Technology NewsTechnology News
Font ResizerAa
Search
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Follow US
  • Cookie Policy (EU)
  • Contact
  • About
© 2025 NEWSLINKER - Powered by LK SOFTWARE
Cybersecurity

Microsoft Patches Critical Zero-Day Vulnerabilities

Highlights

  • Microsoft discloses critical vulnerabilities in latest Patch Tuesday update.

  • Exploited flaws include Windows Installer and Updater, posing significant risks.

  • Urgent updates recommended to mitigate potential security threats.

Samantha Reed
Last updated: 10 September, 2024 - 11:58 pm 11:58 pm
Samantha Reed 8 months ago
Share
SHARE

Microsoft has unveiled its latest security updates, targeting critical vulnerabilities in various Windows products, including Windows Installer and Windows Updater. The announcement encompasses 79 vulnerabilities, seven of which are rated critical, emphasizing the pressing need for users to update their systems promptly. The newly disclosed vulnerabilities pose significant risks, including the potential for attackers to gain full system access.

Contents
Critical Vulnerabilities ExposedPotential for Severe AttacksRisks Associated with ‘Mark of the Web’

Several of these vulnerabilities have been previously reported in various security bulletins, noting their potential to affect out-of-support versions of Windows 10. These past reports highlighted the urgency for users to migrate to supported versions to avoid security risks. The recently revealed exploits, particularly those involving Windows Update and Installer, reaffirm the ongoing challenge in maintaining robust cybersecurity measures.

Critical Vulnerabilities Exposed

Among the critical vulnerabilities, three — CVE-2024-38014, CVE-2024-38217, and CVE-2024-38226 — have already been exploited in the wild. CVE-2024-38014 impacts Windows Installer and could enable attackers to gain system privileges. Michael Baer of SEC Consult Vulnerability Lab discovered this vulnerability. Another significant flaw, CVE-2024-43491, affecting Windows Update, could allow attackers to remove patches and exploit older vulnerabilities, primarily impacting end-of-life Windows 10 products.

Potential for Severe Attacks

Microsoft’s detailed advisory indicates the necessity of deploying the September 2024 Servicing stack update (SSU KB5043936) and Windows security update (KB5043083) to mitigate CVE-2024-43491. Although there are no active exploitations of this vulnerability reported, its ability to undo previous fixes raises significant security concerns. Additionally, CVE-2024-38226, a Microsoft Office Publisher bug, can bypass macro policies to execute malicious files if local privileges are obtained.

Risks Associated with ‘Mark of the Web’

CVE-2024-38217 targets Microsoft’s “Mark of the Web” security feature, which flags files downloaded from the internet. Exploiting this vulnerability could undermine related security features such as SmartScreen and Application Reputation, posing further threats to system integrity. The vulnerability, publicly disclosed and actively exploited, was identified by Elastic Security Labs’ Joe Desimone.

The Cybersecurity and Infrastructure Security Agency (CISA) has responded by adding four of the disclosed vulnerabilities to its Known Exploited Vulnerabilities (KEV) list, underscoring the critical nature of these threats. Security experts advise immediate updates to mitigate potential exploits.

Microsoft’s ongoing efforts to address these vulnerabilities highlight the complexity and evolving nature of cybersecurity threats. Users and administrators must remain vigilant, ensuring timely updates and comprehensive security practices to safeguard their systems. Regularly reviewing and applying security patches can prevent exploitation of these identified vulnerabilities, contributing to a more secure digital environment.

You can follow us on Youtube, Telegram, Facebook, Linkedin, Twitter ( X ), Mastodon and Bluesky

You Might Also Like

Cyberattack Forces PowerSchool to Face Extortion Scandal

CrowdStrike Faces Workforce Reduction Amid Financial Shifts

Authorities Seize DDoS Platforms in Multi-National Operation

Trump Urges Colorado to Release Jailed Clerk Over Election Breach

Google Targets Vulnerabilities in May Security Update

Share This Article
Facebook Twitter Copy Link Print
Samantha Reed
By Samantha Reed
Samantha Reed is a 40-year-old, New York-based technology and popular science editor with a degree in journalism. After beginning her career at various media outlets, her passion and area of expertise led her to a significant position at Newslinker. Specializing in tracking the latest developments in the world of technology and science, Samantha excels at presenting complex subjects in a clear and understandable manner to her readers. Through her work at Newslinker, she enlightens a knowledge-thirsty audience, highlighting the role of technology and science in our lives.
Previous Article Meta and Startups Compete in A.I.-Powered Smart Glasses Market
Next Article Salesforce Unveils Agentic AI at Dreamforce

Stay Connected

6.2kLike
8kFollow
2.3kSubscribe
1.7kFollow

Latest News

Trump Alters AI Chip Export Strategy, Reversing Biden Controls
AI
Solve Wordle’s Daily Puzzle with These Expert Tips
Gaming
US Automakers Boost Robot Deployment in 2024
Robotics
Uber Expands Autonomy Partnership with $100 Million Investment in WeRide
Robotics
EB Games Returns to Canada and Recaptures Nostalgia
Gaming
NEWSLINKER – your premier source for the latest updates in ai, robotics, electric vehicle, gaming, and technology. We are dedicated to bringing you the most accurate, timely, and engaging content from across these dynamic industries. Join us on our journey of discovery and stay informed in this ever-evolving digital age.

ARTIFICAL INTELLIGENCE

  • Can Artificial Intelligence Achieve Consciousness?
  • What is Artificial Intelligence (AI)?
  • How does Artificial Intelligence Work?
  • Will AI Take Over the World?
  • What Is OpenAI?
  • What is Artifical General Intelligence?

ELECTRIC VEHICLE

  • What is Electric Vehicle in Simple Words?
  • How do Electric Cars Work?
  • What is the Advantage and Disadvantage of Electric Cars?
  • Is Electric Car the Future?

RESEARCH

  • Robotics Market Research & Report
  • Everything you need to know about IoT
  • What Is Wearable Technology?
  • What is FANUC Robotics?
  • What is Anthropic AI?
Technology NewsTechnology News
Follow US
About Us   -  Cookie Policy   -   Contact

© 2025 NEWSLINKER. Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Register Lost your password?