Windows Security
The latest Windows Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
Microsoft's December 2024 Patch Tuesday: Addressing 72 Vulnerabilities, Including Critical Zero-Day Flaws
In December 2024, Microsoft released its final Patch Tuesday update, addressing a total of 72 vulnerabilities across various products. Among these, one actively exploited zero-day vulnerability...
Windows 11’s Administrator Protection: A New Era in Enhanced Security and Privilege Management
Introduction Microsoft's Windows 11 continues to advance as the most secure iteration of its operating system. Alongside hardware requirements improvements like TPM 2.0, Windows 11 now introduces a...
CVE-2024-50623: Critical Windows Vulnerability Exposes Users to Cyber Threats
A newly discovered vulnerability, tracked as CVE-2024-50623, has raised significant concerns among Windows users and cybersecurity experts. This critical security flaw, recently added to CISA's Known...
Microsoft December 2024 Patch Tuesday: 71 Fixes, 6 Zero-Days, 3 Exploited
Microsoft's December 2024 Patch Tuesday has arrived, addressing a total of 71 vulnerabilities across its product ecosystem, including critical fixes for Windows, Office, and Azure. This month's...
Emergency Patch Required: Microsoft Update Catalog Bug CVE-2024-49147 Enables Remote SYSTEM Access
Microsoft has issued a critical security alert regarding CVE-2024-49147, a dangerous deserialization vulnerability affecting the Microsoft Update Catalog service. This flaw, rated 9.8 on the CVSS...
December 2024 Patch Tuesday: Fix Critical CLFS & LDAP RCE Flaws Now
Microsoft has released its December 2024 Patch Tuesday updates, addressing critical vulnerabilities in the Common Log File System (CLFS) and Lightweight Directory Access Protocol (LDAP) that could...
National CERT Alerts: Active Exploits Using Windows Zero-Day Steal NTLM Credentials
A newly discovered zero-day vulnerability in Windows operating systems has prompted an urgent advisory from the National Computer Emergency Response Team (CERT). This critical security flaw,...
Microsoft Bolsters Windows Security to Combat NTLM Relay Attacks with New Updates
Microsoft has rolled out critical security enhancements to protect Windows systems against NTLM (NT LAN Manager) relay attacks, a persistent threat vector that has plagued enterprises for decades....
December 2024 Windows Security Update: Microsoft Fixes 72 Critical Vulnerabilities
Microsoft's December 2024 Patch Tuesday has addressed 72 security vulnerabilities across Windows operating systems and related software, including several critical remote code execution flaws that...
Critical Zero-Day NTLM Vulnerability Puts Windows Users at High Risk
New NTLM Vulnerability: Zero-Day Threat to Windows Users Overview A recently discovered zero-day vulnerability in the Windows NTLM (New Technology LAN Manager) authentication protocol poses a...
Critical Windows CLFS Zero-Day CVE-2024-49138 Grants SYSTEM Privileges, Patch Now
Microsoft has disclosed a critical elevation of privilege vulnerability (CVE-2024-49138) affecting the Common Log File System (CLFS) driver in Windows operating systems. This flaw could allow...
Attackers exploit unpatched Windows RDP bug CVE-2024-49128 for full system takeover.
A newly discovered critical vulnerability in Windows Remote Desktop Services (RDS) has put enterprise networks at risk of remote code execution (RCE) attacks. Designated as CVE-2024-49128, this...