You should install the Windows December 2024 security updates right away
Microsoft rolled out the latest security updates as part of its December 2024 Patch Tuesday release, and users with Windows laptops and desktop computers should update their systems as soon as possible. According to the company’s release notes, the latest security updates address a publicly disclosed, actively exploited zero-day vulnerability. It also includes fixes for 30 remote code execution vulnerabilities (16 of which are classified as critical) and 41 other security flaws related to operating system components.
Microsoft fixes Zero-Day vulnerability discovered by Crowdstrike
The security updates that Microsoft rolled out on Tuesday (via BleepingComputer) contain a solution for CVE-2024-49138 (Windows Common Log File System Driver Elevation of Privilege Vulnerability), a publicly disclosed zero-day vulnerability that the company claims was being actively exploited.
The flaw allowed attackers to gain access to system-level privileges on an affected Windows PC, and was discovered by Crowdstrike’s Advanced Research Team. Microsoft did not provide details on how the flaw was exploited, presumably to ensure users have enough time to install the latest security updates.
In addition to the fixes for the actively exploited zero-day vulnerability, Microsoft has also fixed a total of 71 flaws affecting various Windows components. This includes 30 remote code execution vulnerabilities, 16 of which have a ‘critical’ severity rating, and 27 vulnerabilities that could allow attackers to gain elevated privileges on an unpatched Windows PC.
The latest security updates for Windows also include patches for bugs in third-party products. Vendors such as Adobe, Cisco, OpenWrt and SAP have issued security updates, while the US Cybersecurity and Infrastructure Security Agency (CISA) advices about vulnerabilities in industrial control systems of various companies.
Users with Windows 11 PCs will need to install the KB5048667 (24H2) and KB5048685 (23H2) cumulative updates, which include the December 2024 security updates. Users with older machines running Windows 10 will need it KB5048652 (22H2) update.