Microsoft addresses two zero-day vulnerabilities, including 61 security issues in May 2024 security updates

In its May 2024 security updates, Microsoft has patched a total of 61 vulnerabilities across its products, including two zero-day vulnerabilities that were being actively exploited in the wild.

Two zero-day vulnerabilities

Microsoft addresses two zero-day vulnerabilities, including 61 security issues in May 2024 security updates

  1. The first zero-day vulnerability, tracked as CVE-2024-30040, is a security feature bypass vulnerability affecting the Windows MSHTML platform. This vulnerability could allow an attacker to bypass Object Linking and Embedding (OLE) mitigations in Microsoft 365 and Microsoft Office, potentially leading to the execution of malicious code if a user is convinced to open a crafted document.
  2. The second zero-day vulnerability, CVE-2024-30051, is an elevation of privilege vulnerability affecting the Windows Desktop Window Manager (DWM) Core Library. Successful exploitation of this vulnerability could grant an attacker SYSTEM-level privileges, giving them complete control over the affected system.

Both of these zero-day vulnerabilities have been added to the Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities Catalog, and users are strongly urged to apply the necessary patches as soon as possible to prevent further exploitation.

In addition to the zero-day vulnerabilities, Microsoft has addressed one critical vulnerability, CVE-2024-30044, affecting Microsoft SharePoint Server. This remote code execution vulnerability could allow an authenticated attacker with Site Owner privileges to inject and execute arbitrary code on the SharePoint Server.

Remaining vulnerabilities

Microsoft addresses two zero-day vulnerabilities, including 61 security issues in May 2024 security updates

The remaining vulnerabilities patched in the May 2024 security updates range from important to critical severity, affecting various Microsoft products such as Microsoft Office, Windows, Azure, Visual Studio, and more. These vulnerabilities could lead to consequences like denial of service, elevation of privilege, information disclosure, remote code execution, security feature bypass, and spoofing.

Security experts and organizations like CISA strongly recommend that users and administrators promptly install these security updates to protect their systems from potential exploitation. Failing to apply these patches could leave systems vulnerable to attacks, data breaches, and other security incidents.

Microsoft’s commitment to addressing vulnerabilities and releasing timely security updates is crucial in maintaining the security and integrity of its products and protecting users from cyber threats. Regular patching and staying up-to-date with the latest security updates is an essential part of any organization’s cybersecurity strategy.

About The Author


Discover more from Microsoft News Now

Subscribe to get the latest posts sent to your email.