Microsoft released security updates addressing 149 vulnerabilities across Windows and other products, including 67 remote code execution flaws, 3 critical issues, and two zero-days that were already being exploited in the wild. The actively exploited bugs were tracked as CVE-2024-29988, a Windows SmartScreen security feature bypass with a CVSS 8.8, and CVE-2024-26234, a spoofing vulnerability with a CVSS 6.7.
Reports said Water Hydra abused CVE-2024-29988 to deliver malicious files, while CVE-2024-26234 was identified during analysis of a malicious proxy driver operating as a backdoor and signed with a valid Microsoft Windows Hardware Compatibility Publisher certificate. Microsoft published the fixes as part of its March/April 2024 security release materials, and defenders were urged to deploy the updates quickly across affected Microsoft environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft published the March 2024 Mariner release notes in its Security Update Guide. The reference indicates a security update release note event but does not provide an explicit event date in the supplied content.
CVE-2024-26234 was uncovered during analysis of a malicious proxy driver that functioned as a backdoor and was signed with a valid Microsoft Windows Hardware Compatibility Publisher certificate. Microsoft fixed the spoofing vulnerability as part of its April 2024 Patch Tuesday updates.
The actively exploited Windows SmartScreen security feature bypass CVE-2024-29988 was reported as used by the Water Hydra group to launch malicious files. This attribution was included in reporting on Microsoft's April 2024 security updates.
Microsoft's April 2024 Patch Tuesday updates fixed 149 vulnerabilities, including two zero-days reported as actively exploited in the wild: CVE-2024-29988 and CVE-2024-26234. The updates also addressed 67 remote code execution flaws and three critical issues across Windows and other Microsoft products.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.