Microsoft just released a patch for an actively exploited zero day vulnerability in windows – Breaking News & Latest Updates 2026
Skip to main content
R
External Link
Microsoft just released a patch for an actively exploited zero-day vulnerability in Windows.

Update your systems ASAP, as Bleeping Computer points out that today’s Patch Tuesday updates include one for a zero-day flaw already exploited by attackers.

CVE-2024-49138 - Microsoft Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow vulnerability that allows a local attacker to escalate privileges.

Crowdstrike researchers discovered the flaw, and neither they nor Microsoft have released more details, but the vulnerability affects Windows 10, 11, and various versions of Windows Server.

Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.
Comments
Loading comments
Getting the conversation ready...