5 Zero-Day Vulnerabilities in Microsoft’s October Update: Immediate Risk
Active Exploitation of Security Flaws: Two Vulnerabilities Already Exploited in Cyberattacks
In the October update, Microsoft patched 117 security vulnerabilities, including two zero-day flaws currently being exploited in the wild. These vulnerabilities include a bug in the MSHTML browsing engine and the Microsoft Management Console (MMC), both of which allow hackers to perform Remote Code Execution (RCE).
CVE-2024-43573, related to the legacy Internet Explorer browsing engine, was rated as moderate risk; however, experts warn against overlooking it. The second vulnerability, CVE-2024-43572, allows for the exploitation of malicious files to bypass system safeguards via the Microsoft Saved Console (.msc).
Known but Not Yet Exploited: Three Additional Vulnerabilities Publicly Disclosed
Attacks have not yet begun, but it is only a matter of time. Microsoft disclosed three additional vulnerabilities in this update that have not yet been exploited by attackers but could become targets soon.
One of these is CVE-2024-6197, a Remote Code Execution vulnerability in the open-source cURL tool, which security experts warn attackers will quickly attempt to exploit.
The second is the WinLogon vulnerability, CVE-2024-43583—a risk for multilingual organizations. This flaw poses a danger primarily to global organizations or educational institutions. CVE-2024-43583 can be used by attackers for Privilege Escalation on systems with multi-language support; organizations are advised to patch it immediately.
The third is CVE-2024-20659—a security bypass in the Hyper-V system. This vulnerability in Windows’ Hyper-V virtualization platform allows attackers to bypass security restrictions and trigger actions that could compromise the system. Although Microsoft classified this vulnerability as medium severity, experts recommend patching it promptly, especially for organizations using Hyper-V for virtual server management.
Additional Critical Vulnerabilities in the October Update
Critical Security Patches: Immediate Attention Required
Microsoft designated three vulnerabilities in this update as Critical, all of which allow Remote Code Execution (RCE). CVE-2024-43468 in Microsoft Configuration Manager allows attackers to move laterally across the network and breach additional systems.
Another vulnerability, CVE-2024-43533, allows attackers to exploit an RDP vulnerability to execute code on client machines. In this scenario, hackers can set up malicious RDP servers and exploit scans performed by government entities or security firms.
The third critical vulnerability, CVE-2024-43488, exists in the Visual Studio Code extension for Arduino Remote. Successful exploitation of this flaw could allow attackers to execute malicious code on the systems of users utilizing this extension, necessitating an immediate patch.
Recommendations from IPV Security Experts:
1. Install updates promptly – Immediate patching of all vulnerable versions, especially for flaws already being exploited in the wild.
2. Monitor suspicious activity – Deploy monitoring software to detect any suspicious activity interacting with RDP or MSC systems.
3. Backup and data security – Ensure regular data backups and encryption to enhance security posture.
The October update makes it clear that any vulnerability not patched immediately can become an easy pathway for hackers.
For further information: Microsoft Flags 5 Zero-Day Bugs to Patch Immediately (darkreading.com)