{"id":281262,"date":"2024-05-16T06:03:07","date_gmt":"2024-05-16T13:03:07","guid":{"rendered":"https:\/\/sftarticles.wpenginepowered.com\/es\/?p=332489"},"modified":"2025-07-01T16:29:46","modified_gmt":"2025-07-01T23:29:46","slug":"microsoft-fixes-61-security-flaws-in-its-latest-major-update-including-two-serious-zero-day-vulnerabilities","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/microsoft-fixes-61-security-flaws-in-its-latest-major-update-including-two-serious-zero-day-vulnerabilities\/","title":{"rendered":"Microsoft fixes 61 security flaws in its latest major update, including two serious zero-day vulnerabilities"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Microsoft<\/strong> has released a series of security updates that address a total of 61 vulnerabilities in its software, including two <a href=\"https:\/\/en.softonic.com\/articles\/microsoft-fixes-two-zero-day-exploits-that-could-be-used-to-sneak-malware-onto-your-system\" target=\"_blank\" rel=\"noopener\" title=\"\">zero-day vulnerabilities<\/a> that have been <strong>exploited in real-world environments<\/strong>. These patches add to the <strong>30 vulnerabilities fixed in the Edge browser<\/strong> last month, highlighting the severity of the situation.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"Kaspersky Anti-Virus\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/9de631e4-96d2-11e6-be3c-00163ec9f5fa\/1794891465\/kaspersky-kaspersky.png\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Kaspersky Anti-Virus<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/kaspersky.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">DOWNLOAD<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/kaspersky.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Of the <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2024-May\" target=\"_blank\" rel=\"noopener nofollow\" title=\"\">61 fixed vulnerabilities<\/a>, one is critical, 59 are important, and one is of moderate severity. The actively exploited vulnerabilities in real-world environments are <strong>CVE-2024-30040<\/strong> and <strong>CVE-2024-30051<\/strong>. The first one affects the <strong>Windows MSHTML<\/strong> platform and the second one affects the core library of <strong>Windows Desktop Window Manager (DWM)<\/strong>, with potential serious consequences for users.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to Microsoft, an attacker could <strong>execute arbitrary code in the user&#8217;s context<\/strong> if they successfully exploit the CVE-2024-30040 vulnerability. On the other hand, CVE-2024-30051 could allow an attacker to <strong>obtain system privileges<\/strong>, giving them general access to the victim&#8217;s device, according to researchers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The <strong>United States Cybersecurity and Infrastructure Security Agency<\/strong> added these <a href=\"https:\/\/en.softonic.com\/articles\/google-manages-to-solve-one-of-its-biggest-headaches-to-date\" target=\"_blank\" rel=\"noopener\" title=\"\">vulnerabilities<\/a> to its catalog of &#8220;Known Exploited Vulnerabilities,&#8221; highlighting their importance and the need for swift action by public agencies.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"498\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2024\/05\/escritorio-hacker-1024x498-1-1024x498.jpg\" alt=\"\" class=\"wp-image-281266\" srcset=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2024\/05\/escritorio-hacker-1024x498-1-1024x498.jpg 1024w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2024\/05\/escritorio-hacker-1024x498-1-300x146.jpg 300w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2024\/05\/escritorio-hacker-1024x498-1-768x374.jpg 768w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2024\/05\/escritorio-hacker-1024x498-1.jpg 1480w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">In addition to actively exploited vulnerabilities, Microsoft has also fixed several <strong>remote code execution flaws<\/strong>, including those affecting the <strong>Windows Mobile Broadband driver<\/strong> and the <strong>Windows Remote Routing and Access Service (RRAS)<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There are also <strong>privilege escalation vulnerabilities<\/strong> in various Windows components, such as the Common Log File System (CLFS) driver, Win32k, Windows Search Service, and Windows Kernel. These vulnerabilities are extremely serious, as they could be exploited by wrongdoers to <strong>gain access to computer systems<\/strong> of their victims.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In March 2024, the cybersecurity company <strong>Kaspersky<\/strong> revealed that cybercriminals were actively exploiting vulnerabilities that have fortunately already been patched in Windows, highlighting the importance of applying security patches as soon as possible.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"Kaspersky Anti-Virus\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/9de631e4-96d2-11e6-be3c-00163ec9f5fa\/1794891465\/kaspersky-kaspersky.png\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Kaspersky Anti-Virus<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/kaspersky.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">DOWNLOAD<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/kaspersky.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft has released a series of security updates that address a total of 61 vulnerabilities in its software, including two zero-day vulnerabilities that have been exploited in real-world environments. These patches add to the 30 vulnerabilities fixed in the Edge browser last month, highlighting the severity of the situation. Of the 61 fixed vulnerabilities, one &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/microsoft-fixes-61-security-flaws-in-its-latest-major-update-including-two-serious-zero-day-vulnerabilities\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Microsoft fixes 61 security flaws in its latest major update, including two serious zero-day vulnerabilities&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9256,"featured_media":281264,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":1},"categories":[1015],"tags":[],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-281262","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/281262","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9256"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=281262"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/281262\/revisions"}],"predecessor-version":[{"id":313155,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/281262\/revisions\/313155"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/281264"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=281262"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=281262"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=281262"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=281262"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=281262"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=281262"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}