Close Menu
Alpha Leaders
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
What's On
Humana To Divest End-Of-Life Care Business For 0 Million

Humana To Divest End-Of-Life Care Business For $900 Million

11 June 2026
Anthropic accused of ‘secret sabotage’ as Claude Fable 5 silently limits AI research capabilities

Anthropic accused of ‘secret sabotage’ as Claude Fable 5 silently limits AI research capabilities

11 June 2026
NYT ‘Pips’ Hints, Answers And Walkthrough For Thursday, June 11

NYT ‘Pips’ Hints, Answers And Walkthrough For Thursday, June 11

11 June 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Alpha Leaders
newsletter
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
Alpha Leaders
Home » Windows Users Must Update Now As Microsoft Confirms 4 New Zero-Days
Innovation

Windows Users Must Update Now As Microsoft Confirms 4 New Zero-Days

Press RoomBy Press Room13 November 20244 Mins Read
Facebook Twitter Copy Link Pinterest LinkedIn Tumblr Email WhatsApp
Windows Users Must Update Now As Microsoft Confirms 4 New Zero-Days

This week, Microsoft has confirmed another major discovery of security vulnerabilities impacting users of its products. Amidst the blur that is a report of more than 90 security issues in all, there sit four zero-day vulnerabilities and two of these, Microsoft confirmed, are being actively exploited by threat actors. Here’s what you need to know and do.

Microsoft Confirms November 2024 Patchy Tuesday Complete With Four Zero-Day Vulnerabilities

Microsoft has a very Microsoft-centric way of assessing a zero-day threat. Whereas most security professionals agree that the term relates to a vulnerability that has already been exploited by the time the vendor or any security professional discovers it, Microsoft instead uses a definition of a vulnerability that has been publicly disclosed as well as those under active attack. So it is that Microsoft includes four zero-days in the November 2024 Patch Tuesday security updates release. Of these, however, only two are known to have been under active exploitation at the time of the Patch Tuesday disclosure on Nov. 12. Of these two, one hits both markers of being publicly disclosed and actively under attack.

CVE 2024-43451 is a NT LAN Manager hash disclosure spoofing vulnerability that can expose a crucial part of the NTLM authentication protocol to an attacker. “NTLM hashing is a method used to protect passwords by converting them into a fixed-length string of characters, which is then transmitted for authentication purposes,” Ryan Braunstein, the team lead of security operations at Automox, said. In other words, when the hash is disclosed it allows the attacker to potentially authenticate as the user. While confirmed and under active exploitation, Braunstein said that the zero-day vulnerability requires user interaction. “Specifically, a user needs to open a crafted file that an attacker might send through phishing attempts,” Braunstein said.

Meanwhile, CVE 2024-49039 is a Windows Task Scheduler elevation of privilege vulnerability that could allow an attacker to, unsurprisingly, elevate their privileges on the targeted Windows system. “This elevation of privilege vulnerability exploits Remote Procedure Call functions,” Henry Smith, a senior security engineer at Automox, said, “which are essential for executing commands and transferring data between a client and server.” That attacker would first need to gain access to the target system, Smith explained, and then run a malicious application to exploit the vulnerability. “To mitigate this vulnerability,” which has functional exploit code already out there, Smith said, “patching is your most effective strategy.”

Two Microsoft Security Vulnerabilities Rate As 9.8 On The Impact Severity Scale

The big news, however, should be aimed in the direction of not one, but two, security vulnerabilities that hit a massive 9.8 on the impact severity scale, according to Tyler Reguly, associate director for security research and development at Fortra. “While the Common Vulnerability Scoring System is not an indicator of risk,” Reguly said, “scores that are a 9.8 are often pretty telling of where the issue is.” In the case of CVE-2024-43498, it’s a vulnerability in .NET that allows an unauthenticated, remote attacker to exploit .NET webapps with malicious requests. “Similarly, CVE-2024-43639 allows an unauthenticated attacker to attack Windows Kerberos in order to gain code execution,” Reguly warned.

Microsoft Windows Users Should Update Now

With the zero-days and four critical-rated vulnerabilities included in the mix, the Patch Tuesday security updates affect Microsoft users of the Windows OS, Office, SQL Server, Exchange Server, .Net and Visual Studio. “The Microsoft Windows OS updates should be your top priority this month as they resolve both known and exploited vulnerabilities,” Chris Goettl, vice president of security product management at Ivanti, said. Microsoft Exchange Server should be a priority for organizations running Exchange Server, Goetti concluded.

Microsoft Cyber Attack Microsoft Security Microsoft Windows Security Microsoft Windows Update Microsoft Zero-Day Attack Patch Tuesday Security Update Windows Attack windows update
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link

Related Articles

Humana To Divest End-Of-Life Care Business For 0 Million

Humana To Divest End-Of-Life Care Business For $900 Million

11 June 2026
NYT ‘Pips’ Hints, Answers And Walkthrough For Thursday, June 11

NYT ‘Pips’ Hints, Answers And Walkthrough For Thursday, June 11

11 June 2026
Today’s Wordle #1818 Hints And Answer For Thursday, June 11

Today’s Wordle #1818 Hints And Answer For Thursday, June 11

10 June 2026
Millions Of Samsung Galaxy Phones Are In Line For A Free Upgrade

Millions Of Samsung Galaxy Phones Are In Line For A Free Upgrade

10 June 2026
Apple iOS 27 Release Creates A Price Problem For iPhone 15 Owners

Apple iOS 27 Release Creates A Price Problem For iPhone 15 Owners

10 June 2026
Answers Explained For Thursday, June 11 (#1,096)

Answers Explained For Thursday, June 11 (#1,096)

10 June 2026
Don't Miss
Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

By Press Room27 December 2024

Every year, millions of people unwrap Christmas gifts that they do not love, need, or…

Exclusive: DeFi platform Azura launches after raising .9 million from Initialized

Exclusive: DeFi platform Azura launches after raising $6.9 million from Initialized

22 October 2024
Sam Altman’s World Wants To Scan Your Eyes To Prove You’re Human

Sam Altman’s World Wants To Scan Your Eyes To Prove You’re Human

22 October 2024
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Latest Articles
Today’s Wordle #1818 Hints And Answer For Thursday, June 11

Today’s Wordle #1818 Hints And Answer For Thursday, June 11

10 June 20262 Views
The curse of Trump watching sports in person: the home team seems to always lose

The curse of Trump watching sports in person: the home team seems to always lose

10 June 20262 Views
Millions Of Samsung Galaxy Phones Are In Line For A Free Upgrade

Millions Of Samsung Galaxy Phones Are In Line For A Free Upgrade

10 June 20261 Views
Digital sovereignty isn’t the same thing as digital isolation. Asia’s governments should be careful

Digital sovereignty isn’t the same thing as digital isolation. Asia’s governments should be careful

10 June 20262 Views

Recent Posts

  • Humana To Divest End-Of-Life Care Business For $900 Million
  • Anthropic accused of ‘secret sabotage’ as Claude Fable 5 silently limits AI research capabilities
  • NYT ‘Pips’ Hints, Answers And Walkthrough For Thursday, June 11
  • Gates testifies on Epstein: Fortune reported payments to his ex-girlfriend, $1M Microsoft deal
  • Today’s Wordle #1818 Hints And Answer For Thursday, June 11

Recent Comments

No comments to show.
About Us
About Us

Alpha Leaders is your one-stop website for the latest Entrepreneurs and Leaders news and updates, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
Humana To Divest End-Of-Life Care Business For 0 Million

Humana To Divest End-Of-Life Care Business For $900 Million

11 June 2026
Anthropic accused of ‘secret sabotage’ as Claude Fable 5 silently limits AI research capabilities

Anthropic accused of ‘secret sabotage’ as Claude Fable 5 silently limits AI research capabilities

11 June 2026
NYT ‘Pips’ Hints, Answers And Walkthrough For Thursday, June 11

NYT ‘Pips’ Hints, Answers And Walkthrough For Thursday, June 11

11 June 2026
Most Popular
Gates testifies on Epstein: Fortune reported payments to his ex-girlfriend, M Microsoft deal

Gates testifies on Epstein: Fortune reported payments to his ex-girlfriend, $1M Microsoft deal

11 June 20261 Views
Today’s Wordle #1818 Hints And Answer For Thursday, June 11

Today’s Wordle #1818 Hints And Answer For Thursday, June 11

10 June 20262 Views
The curse of Trump watching sports in person: the home team seems to always lose

The curse of Trump watching sports in person: the home team seems to always lose

10 June 20262 Views

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • March 2022
  • January 2021
  • March 2020
  • January 2020

Categories

  • Blog
  • Business
  • Entrepreneurs
  • Global
  • Innovation
  • Leadership
  • Living
  • Money & Finance
  • News
  • Press Release
© 2026 Alpha Leaders. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.