Microsoft published security advisories for several remote code execution vulnerabilities affecting core Windows components and the OmniParser product. The issues include CVE-2024-21341 in the Windows Kernel, CVE-2024-30074 in the Windows Link Layer Topology Discovery Protocol, CVE-2024-49080 in the Windows IP Routing Management Snap-in, and CVE-2025-55322 in OmniParser, expanding the set of Microsoft-tracked flaws that could allow attackers to run arbitrary code on vulnerable systems.
The affected components span low-level operating system functionality, network discovery and routing management, and a separate Microsoft product, indicating exposure across both endpoint and administrative environments. Microsoft assigned each issue a formal Security Update Guide entry and released fixes through its advisory process, underscoring the need for organizations to review affected assets, prioritize patch deployment, and validate that Windows systems and OmniParser installations are updated against these RCE risks.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft released a Security Update Guide entry for CVE-2025-55322, an OmniParser remote code execution vulnerability.
Microsoft released a Security Update Guide entry for CVE-2024-49080, a Windows IP Routing Management Snap-in remote code execution vulnerability.
Microsoft released a Security Update Guide entry for CVE-2024-30074, a Windows Link Layer Topology Discovery Protocol remote code execution vulnerability.
Microsoft released a Security Update Guide entry for CVE-2024-21341, a Windows Kernel remote code execution vulnerability.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.