Microsoft on Tuesday shared security updates on 117 common vulnerabilities and exposures, including two that are being actively exploited, according to the company.

The actively exploited vulnerabilities relate to the Microsoft Management Console (CVE-2024-43572) and the Windows MSHTML Platform (CVE-2024-43573), the company said.

The list includes five publicly disclosed zero-days in total, as part of 28 elevation-of-privilege vulnerabilities, seven security feature bypasses, 43 remote code execution vulnerabilities, six information disclosure vulnerabilities, 26 denial-of-service vulnerabilities and seven spoofing vulnerabilities, according to Bleeping Computer.

The MSHTML vulnerability exploits an issue with the Internet Explorer web browser, making it the fourth such MSHTML vulnerability to be exploited in the wild in 2024, Brian Krebs reported Tuesday. Security Week reported that the MSHTML platform has been widely targeted by ransomware and advanced nation-state hacking teams.

The Microsoft Management Console vulnerability allows attackers who leverage malicious Microsoft Saved Console (MSC) files to execute remote code on targeted systems, according to Security Week.

The post Microsoft offers updates on 117 vulnerabilities on Patch Tuesday appeared first on CyberScoop.

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

California AI Safety Bill Vetoed

October 2, 2024 0 Comments 0 tags

Governor Newsom has vetoed the state’s AI safety bill. I have mixed feelings about the bill. There’s a lot to like about it, and I want governments to regulate in

Mozilla Drops Onerep After CEO Admits to Running People-Search Networks

March 22, 2024 0 Comments 0 tags

The nonprofit organization that supports the Firefox web browser said today it is winding down its new partnership with Onerep, an identity protection service recently bundled with Firefox that offers

Tech companies pledge to protect 2024 elections from AI-generated media

February 16, 2024 0 Comments 0 tags

A coalition of major technology companies committed on Friday to limit the malicious use of deepfakes and other forms of artificial intelligence to manipulate or deceive voters in democratic elections.