Microsoft warns of active MMC exploit

MMC exploit

Microsoft issued an urgent warning on Tuesday about an actively exploited code execution vulnerability in a Windows component used for system configuration and monitoring. The zero-day vulnerability is documented as a remote code execution issue in Microsoft Management Console (MMC), a commonly targeted component of the Windows operating system. Redmond’s security response team warned that attackers are leveraging malicious Microsoft Saved Console (MSC) files to execute remote code on targeted Windows systems.

The flaw carries a CVSS severity score of 7.8/10 and headlines a hefty Patch Tuesday rollout to cover at least 119 documented vulnerabilities throughout the Windows ecosystem. As is customary, Microsoft did not share IOCs (indicators of compromise) or any other telemetry data to help defenders hunt for signs of infections. This is the 23rd time this year Microsoft has had to respond to zero-day exploitation prior to the availability of patches.

The October batch of patches also covers critical-severity flaws in the Visual Studio Code extension for Arduino, the Remote Desktop Protocol Server, and the Microsoft Configuration Manager.

Microsoft issues critical exploit warning

All these vulnerabilities are documented as “remote code execution” issues.

Microsoft also flagged for urgent attention, warning that a flaw in the Windows MSHTML platform is also in the “exploitation detected” category. The MSHTML platform is used by Internet Explorer mode in Microsoft Edge as well as other applications through WebBrowser control and has been targeted by ransomware and hacking teams. The world’s largest software maker also urged Windows users to prioritize fixes for remote code execution bugs in the Microsoft Configuration Manager and Remote Desktop Protocol Server components.

The company also pushed out patches for several publicly known issues, including a Winlogon privilege escalation flaw (CVE-2024-43583), a Windows Hyper-V security feature bypass bug (CVE-2024-20659), and a code execution problem in the Windows cURL implementation. Separately on Patch Tuesday, Adobe rolled out updates to fix security defects in multiple product lines and warned of code execution risks on Windows and macOS platforms. The Adobe rollout includes a critical-severity patch documenting 25 vulnerabilities in Adobe Commerce that expose businesses to code execution, privilege escalation, and security feature bypass attacks.

Two of the 25 vulnerabilities carry a CVSS severity score of 9.8/10.

Feeling stuck in self-doubt?

Stop trying to fix yourself and start embracing who you are. Join the free 7-day self-discovery challenge and learn how to transform negative emotions into personal growth.

Join Free Now

Picture of Noland Anderson

Noland Anderson

Noland Anderson is the driving force behind a cutting-edge technology company at the forefront of digital transformation. As the founder and CEO, Noland combines his deep expertise in tech with a passion for innovation to deliver groundbreaking solutions to clients worldwide.

RECENT ARTICLES

TRENDING AROUND THE WEB

People who put off charging their phone until it’s at 1% tend to share these 8 unique traits

People who put off charging their phone until it’s at 1% tend to share these 8 unique traits

Global English Editing

People who prefer to stay home on weekends over going out typically display these 9 unique personality traits

People who prefer to stay home on weekends over going out typically display these 9 unique personality traits

Global English Editing

People who talk too much when they’re nervous usually display these 7 behaviors, says psychology

People who talk too much when they’re nervous usually display these 7 behaviors, says psychology

Global English Editing

7 things boomers do now that their younger selves would never believe

7 things boomers do now that their younger selves would never believe

Global English Editing

If you go to bed at the same time every night, even on weekends, psychology says you likely possess these 7 traits

If you go to bed at the same time every night, even on weekends, psychology says you likely possess these 7 traits

Global English Editing

8 simple tricks I used to cut my screen time in half

8 simple tricks I used to cut my screen time in half

Global English Editing