
Microsoft Patches Actively Exploited Zero-Day and Vulnerabilities with Public PoCs in July Update
Microsoft's July Patch Tuesday addressed 132 vulnerabilities, including an actively exploited zero-day (CVE-2024-38112) and two flaws with public proof-of-concept (PoC) exploits (CVE-2024-38074 and CVE-2024-38090). The zero-day, reported by the National Security Agency (NSA), is a Windows MSHTML Platform Remote Code Execution Vulnerability. The other two vulnerabilities affect Windows Hyper-V and Windows Imaging Component, respectively. The availability of PoC exploits for these vulnerabilities underscores the criticality of timely patching. Public PoCs can accelerate exploitation by threat actors, increasing the risk for unpatched systems. In 2024 alone, Microsoft has patched over 1,150 vulnerabilities, highlighting the continuous effort required to maintain system security. From a cybersecurity perspective, the exploitation of zero-days and the availability of PoCs emphasize the importance of a robust patch management process. Organizations should prioritize applying these patches to mitigate potential risks. The involvement of the NSA in reporting the zero-day also underscores the severity and potential impact of this vulnerability.