Microsoft's December Patch Tuesday Addresses 72 Vulnerabilities, Including Active Zero-Day

1 min read
Source: The Hacker News
Microsoft's December Patch Tuesday Addresses 72 Vulnerabilities, Including Active Zero-Day
Photo: The Hacker News
TL;DR Summary

Microsoft's latest Patch Tuesday update addresses 72 security vulnerabilities, including a critical privilege escalation flaw in the Windows Common Log File System (CLFS) that has been actively exploited. This flaw, CVE-2024-49138, is the fifth such CLFS vulnerability exploited since 2022. Microsoft is implementing new security measures, such as HMAC, to mitigate these risks. Additionally, Microsoft plans to phase out NTLM in favor of Kerberos to enhance security. Other vendors, including Adobe and Google, have also released security updates.

Share this article

Reading Insights

Total Reads

0

Unique Readers

1

Time Saved

5 min

vs 6 min read

Condensed

92%

1,01778 words

Want the full story? Read the original article

Read on The Hacker News