Microsoft has released a series of security updates that address a total of 61 vulnerabilities in its software, including two zero-day vulnerabilities that have been exploited in real-world environments. These patches add to the 30 vulnerabilities fixed in the Edge browser last month, highlighting the severity of the situation.
Of the 61 fixed vulnerabilities, one is critical, 59 are important, and one is of moderate severity. The actively exploited vulnerabilities in real-world environments are CVE-2024-30040 and CVE-2024-30051. The first one affects the Windows MSHTML platform and the second one affects the core library of Windows Desktop Window Manager (DWM), with potential serious consequences for users.
According to Microsoft, an attacker could execute arbitrary code in the user’s context if they successfully exploit the CVE-2024-30040 vulnerability. On the other hand, CVE-2024-30051 could allow an attacker to obtain system privileges, giving them general access to the victim’s device, according to researchers.
The United States Cybersecurity and Infrastructure Security Agency added these vulnerabilities to its catalog of “Known Exploited Vulnerabilities,” highlighting their importance and the need for swift action by public agencies.

In addition to actively exploited vulnerabilities, Microsoft has also fixed several remote code execution flaws, including those affecting the Windows Mobile Broadband driver and the Windows Remote Routing and Access Service (RRAS).
There are also privilege escalation vulnerabilities in various Windows components, such as the Common Log File System (CLFS) driver, Win32k, Windows Search Service, and Windows Kernel. These vulnerabilities are extremely serious, as they could be exploited by wrongdoers to gain access to computer systems of their victims.
In March 2024, the cybersecurity company Kaspersky revealed that cybercriminals were actively exploiting vulnerabilities that have fortunately already been patched in Windows, highlighting the importance of applying security patches as soon as possible.