Today is Microsoft's May 2024 Patch Tuesday, which includes security updates for 61 flaws and three actively exploited or publicly disclosed zero days.
The total count of 61 flaws does not include 2 Microsoft Edge flaws fixed on May 2nd and four fixed on May 10th. To learn more about the non-security updates released today, you can review our dedicated articles on the new Windows 11 KB5037771 cumulative update and the Windows 10 KB5037768 update.
This month's Patch Tuesday fixes two actively exploited and one publicly disclosed zero-day vulnerabilities.
Microsoft classifies a zero-day as a flaw publicly disclosed or actively exploited with no official fix available.
Microsoft has fixed an actively exploited Windows DWM Core Library flaw that provides SYSTEM privileges.
A short report from Kaspersky states that recent Qakbot malware phishing attacks used malicious documents to exploit the flaw and gain SYSTEM privileges on Windows devices.
Microsoft says a denial of service flaw in Microsoft Visual Studio tracked as CVE-2024-30046 was publicly disclosed as well.
Adobe has released security updates for After Effects, Photoshop, Commerce, InDesign, and more.
Apple backported an RTKit zero-day to older devices and fixed a Safari WebKit zero-day flaw exploited at Pwn2Own.
Cisco released security updates for its IP phone products.
F5 releases security updates for two high-severity BIG-IP Next Central Manager API flaws.
Google released an emergency update to fix the sixth zero-day of 2024.
TinyProxy fixes a critical remote code execution flaw that was disclosed by Cisco.
VMware fixes three zero-day bugs exploited at Pwn2Own 2024.
We will no longer be linking to SAP's Patch Tuesday security updates as they have placed them behind a customer login.
Below is the complete list of resolved vulnerabilities in the May 2024 Patch Tuesday updates.
Windows 10 KB5036892 update released with 23 new fixes, changes.
Windows 11 KB5037771 update released with 30 fixes, changes.
Windows 11 KB5036893 update released with 29 changes, Moment 5 features.
Critical Rust flaw enables Windows command injection attacks.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Tue, 14 May 2024 17:50:28 +0000