Microsoft Windows 11 and Windows 10 Updated With Fix for Actively Exploited Zero-Day Vulnerability

Microsoft has patched a publicly disclosed zero-day vulnerability that was actively exploited to gain system-level privileges on Windows PCs.

Advertisement
Written by David Delima | Updated: 11 December 2024 12:32 IST
Highlights
  • Microsoft has fixed several critical Windows security flaws
  • Both Windows 11 and Windows 10 have received security fixes
  • Microsoft has released patches for 71 security vulnerabilities

PCs running Windows 11 and Windows 10 will receive mandatory updates with fixes for the flaws

Photo Credit: Microsoft

Microsoft has rolled out its latest security updates as part of the December 2024 Patch Tuesday release, and users with Windows laptops and desktop computers should update their systems as soon as possible. According to the company's release notes, the latest security updates fix a publicly disclosed, actively exploited zero-day vulnerability. It also includes fixes for 30 remote code execution vulnerabilities — of these, 16 are designated as critical — and 41 other security flaws related to operating system components.

Microsoft Fixes Zero-Day Vulnerability Discovered by Crowdstrike

The security updates rolled out by Microsoft on Tuesday (via BleepingComputer) include a fix for CVE-2024-49138 (Windows Common Log File System Driver Elevation of Privilege Vulnerability), which is a publicly disclosed zero-day vulnerability that was actively exploited, according to the company.

The flaw allowed attackers to gain access to system-level privileges on an affected Windows PC, and was discovered by Crowdstrike's Advanced Research Team. Details on how the flaw was exploited were not provided by Microsoft, presumably to ensure that users have enough time to install the latest security updates.

Advertisement

In addition to the fixes for the actively exploited zero-day vulnerability, Microsoft has also patched a total of 71 flaws affecting various Windows components. This includes 30 remote code execution vulnerabilities, out of which 16 have a 'Critical' severity rating, and 27 vulnerabilities that would enable attackers to gain elevated privileges on an unpatched Windows PC.

Advertisement

The latest security updates for Windows also include patches for flaws in third party products. Vendors like Adobe, Cisco, OpenWrt, and SAP have issued security updates, while the US Cybersecurity and Infrastructure Security Agency (CISA) has published advisories on vulnerabilities in industrial control systems from various companies.

Users with Windows 11 PCs will need to install the KB5048667 (24H2) and KB5048685 (23H2) cumulative updates, which contain the December 2024 security updates. Users with older machines that are running Windows 10 will need to install the KB5048652 (22H2) update.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Here's When the Realme 16 Pro Series Will Launch in India
  2. OTT Releases This Week: Thamma, Mrs Deshpande, Raat Akeli Hai The Bansal Murders, and More
  3. Oppo Reno 15 Pro Mini Tipped to Launch as First Compact Reno Smartphone
  4. Redmi Pad 2 Pro 5G Will Launch in India Soon: See Expected Features
  5. Google's Pixel Upgrade Program Lets You Get the Latest Model Every Year
  6. Samsung Announces Exynos 2600 as World's First 2nm Chipset
  7. Raju Weds Rambai Now Streaming Online: What You Need to Know
  8. Naughty Dog Working Overtime as Intergalactic Targets Mid-2027 Launch: Report
  9. Oppo Pad Air 5 Launch Date Announced: See Expected Features
  10. Meta's New AI Models Could Challenge Google, OpenAI in Image and Video Generation
  1. Meta Reportedly Building Three New Generative AI Models With Focus on Image and Video Generation
  2. Google Pixel Upgrade Program Launched in India With Assured Buyback of Pixel 10 Series Models
  3. Intergalactic: The Heretic Prophet Targeting Mid-2027 Launch as Naughty Dog Orders Overtime: Report
  4. Apple's Foldable iPhone Shipments May Slip to 2027 Despite 2026 Launch, Analyst Says
  5. Realme 16 Pro Series India Launch Date Announced: See Expected Specifications, Features
  6. Google Brings SynthID-Powered Deepfake AI Video Detection Tool to Gemini App
  7. Dreame E1 Phone to Reportedly Debut With 108-Megapixel Camera and 5,000mAh Battery: Expected Specifications
  8. Oppo Pad Air 5 Launch Date, Colourways, Storage Options Revealed: See Expected Specifications, Features
  9. Raju Weds Rambai Now Streaming Online: What You Need to Know
  10. The Fifty OTT Release: When and Where to Watch This High-Stakes Reality Show Online?
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.