Advertisement

Microsoft offers updates on 117 vulnerabilities on Patch Tuesday

The vulnerabilities are tied to the Microsoft Management Console and Windows MSHTML Platform.
Microsoft Power Pages
A logo of US company Microsoft is displayed during the Vivatech technology startups and innovation fair, at the Porte de Versailles exhibition center in Paris, on May 22, 2024. (Photo by JULIEN DE ROSA / AFP / Getty Images)

Microsoft on Tuesday shared security updates on 117 common vulnerabilities and exposures, including two that are being actively exploited, according to the company.

The actively exploited vulnerabilities relate to the Microsoft Management Console (CVE-2024-43572) and the Windows MSHTML Platform (CVE-2024-43573), the company said.

The list includes five publicly disclosed zero-days in total, as part of 28 elevation-of-privilege vulnerabilities, seven security feature bypasses, 43 remote code execution vulnerabilities, six information disclosure vulnerabilities, 26 denial-of-service vulnerabilities and seven spoofing vulnerabilities, according to Bleeping Computer.

The MSHTML vulnerability exploits an issue with the Internet Explorer web browser, making it the fourth such MSHTML vulnerability to be exploited in the wild in 2024, Brian Krebs reported Tuesday. Security Week reported that the MSHTML platform has been widely targeted by ransomware and advanced nation-state hacking teams.

Advertisement

The Microsoft Management Console vulnerability allows attackers who leverage malicious Microsoft Saved Console (MSC) files to execute remote code on targeted systems, according to Security Week.

AJ Vicens

Written by AJ Vicens

AJ covers nation-state threats and cybercrime. He was previously a reporter at Mother Jones. Get in touch via Signal/WhatsApp: (810-206-9411).

Latest Podcasts