Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Microsoft Patches Vulnerabilities in Windows Defender, Update Catalog 

Microsoft has patched potentially critical vulnerabilities in Update Catalog and Windows Defender on the server side. 

Microsoft on Thursday informed customers that two potentially critical vulnerabilities have been patched in Update Catalog and Windows Defender.

The tech giant has released advisories for each flaw and assigned CVE identifiers, but it’s only for transparency purposes as the issues have been fully mitigated and users do not need to take any action. 

The Windows Defender vulnerability, tracked as CVE-2024-49071, has a maximum severity rating of ‘critical’, but based on its CVSS score it’s a medium-severity issue. It could have led to information disclosure, specifically the exposure of file content.

“Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker to disclose information over a network,” Microsoft explained. 

The vulnerability in Update Catalog, which provides a listing of updates that can be distributed over a corporate network, was a privilege escalation issue that had critical severity based on its CVSS score. The flaw is tracked as CVE-2024-49147.

“Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver,” Microsoft said in its advisory.

Advertisement. Scroll to continue reading.

The company’s advisories indicate that the details of these flaws have not been disclosed and there is no indication of malicious exploitation prior to the implementation of patches.

Microsoft is now regularly informing customers about vulnerabilities patched on the server side that do not require any user action. The company has decided to assign CVE identifiers to cloud service vulnerabilities for transparency. 

While these vulnerabilities may not seem important, the company admitted in such an advisory last month that CVE-2024-49035, a high-severity vulnerability in its Partner Network website, was exploited in attacks before it was patched. 

Google Cloud also decided recently to assign CVE identifiers to critical vulnerabilities found in its products, even if they do not require user action.    

Related: Microsoft Patches Vulnerabilities in Power Platform, Imagine Cup Site

Related: Microsoft Ships Urgent Patch for Exploited Windows CLFS Zero-Day

Related: Microsoft MFA Bypassed via AuthQuake Attack

Related: Microsoft Bets $10,000 on Prompt Injection Protections of LLM Email Client

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.