Cashed-up ransomware criminals may exploit more zero days while potential blanket ransomware payment bans hang over defenders like a shadow.
Category: Rapid7
Adam Barnett, CVE-2024-49112, CVE-2024-49138, Fortra, Global Security News, Immersive Labs, LDAP, Lightweight Directory Access Protocol, Microsoft Patch Tuesday December 2024, Other, Rapid7, Rob Reeves, Tenable, Tyler Reguly, Windows Common Log File System (CLFS) driver
Patch Tuesday, December 2024 Edition
Microsoft today released updates to plug at least 70 security holes in Windows and Windows software, including one vulnerability that is already being exploited in active attacks. The zero-day seeing exploitation involves CVE-2024-49138, a security weakness in the Windows Common Log File System (CLFS) driver — used by applications to write transaction logs — that…