Microsoft released its December security updates to address 72 vulnerabilities across Windows, Office, SharePoint, Microsoft 365 Apps, System Center Operations Manager, and related platforms, including 31 remote code execution flaws. The most severe issues affect Windows Remote Desktop Services and Client, Windows LDAP, Hyper-V, Microsoft Message Queuing, and LSASS, with multiple bugs rated critical because they could allow remote compromise of affected systems.
The update bundle also fixes CVE-2024-49138, a privilege-escalation flaw in the Windows Common Log File System Driver (CLFS) that was reported as actively exploited in the wild and could let an authenticated attacker gain SYSTEM privileges. Microsoft published the release through its Security Update Guide and Mariner release notes, while defenders were urged to prioritize rapid deployment of the December patches to reduce exposure to both active exploitation and high-impact remote code execution risks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The December 2024 Microsoft security update notice highlighted CVE-2024-49138 in the Windows Common Log File System Driver as actively exploited in the wild. The flaw allows an authenticated attacker to escalate privileges to SYSTEM.
Microsoft issued its December 2024 Patch Tuesday updates, addressing 72 vulnerabilities across its product portfolio, including 17 critical flaws and 31 remote code execution issues. The affected products include Windows desktop and server versions, Office, SharePoint, Microsoft 365 Apps, and System Center Operations Manager.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.