+254 716148341
info@nc4.go.ke
Follow us:
NC4 Kenya - National Cyber Security Agency

FEATURED CYBER ALERT

Alert: Critical Endpoint Vulnerability in Widely Used Enterprise Software

A high-severity vulnerability is being exploited in the wild. Urgent patching is advised.

Alert: Critical Endpoint Vulnerability in Widely Used Enterprise Software

NC4 Logo

Microsoft Security Update

Microsoft has released security updates to address vulnerabilities in various software products

ARTICLE META

Alert

October 24, 2024

2 min read

NC4 Communications

Back to newsroom
Microsoft Security Update

ALERT · OCTOBER 24, 2024

Microsoft Security Update

Microsoft has released security updates to address vulnerabilities in various software products

Microsoft Security Updates – October 2024

Overview: Microsoft has released security updates to address vulnerabilities in various software products, including:

  • Windows OS: 10 and 11
  • Windows Server: 2016, 2019, 2022
  • Microsoft SQL Server: 2019, 2022
  • Microsoft Office: 2016, 2019, Microsoft 365

These updates fix multiple vulnerabilities, including five zero-day vulnerabilities

  • CVE-2024-43573
  • CVE-2024-43572
  • CVE-2024-6197
  • CVE-2024-20659
  • CVE-2024-43583

Security Risks: Exploitation of these vulnerabilities could allow authenticated attackers to remotely take control of systems, executing malicious code with elevated privileges.

Recommended Actions: The National Computer and Cybercrimes Coordination Committee (NC4) advises users and administrators to:

  1. Apply Security Patches: Implement the latest security updates immediately to prevent unauthorized control over systems.
  1. Upgrade Software: Ensure all installed Microsoft software is updated to the latest supported version for ongoing support and security patches. Immediate upgrades are required for:
  • Windows OS: Vista, XP, 7, 8
  • Windows Server: 2003, 2003 RE, 2008, 2008 RE, 2008 SP2, 2012, 2012 R2
  • Exchange Server: 2003, 2007, 2010, 2013
  • Microsoft SQL Server: 2005, 2008, 2012
  • Microsoft Office: 2013
  1. Backup Data: Ensure a current and tested backup of your data is available before performing any updates.

For the full list of security patches, refer to the Microsoft Security Update Guide.


Back to newsroom