Cyberthreats/Incidents

Trending vulnerability digest October 2024

Trending vulnerability digest October 2024

In October, we classified four vulnerabilities as trending. These are the most dangerous security flaws that attackers are exploiting today or may start exploiting in the near future.

In October, we classified four vulnerabilities as trending that we consider the most dangerous flaws currently popular among attackers or at risk of exploitation in the near future.

Three vulnerabilities were discovered in Microsoft solutions. The first, CVE-2024-43573, affects the MSHTML browser engine for processing and displaying HTML pages and can be used in phishing attacks. Exploitation of the vulnerability may lead to confidential information leaks. The next two vulnerabilities (CVE-2024-35250, CVE-2024-30090) allow attackers to escalate privileges to the maximum SYSTEM level in the Windows operating system. After gaining full control of a node, the attacker can follow through on their other goals.

The fourth vulnerability (CVE-2024-31982) is critical and affects XWiki. When exploited, attackers can use remote code execution (RCE) on the server to gain complete control over the system or its individual components, inject malware, disrupt host operations, or steal confidential data.

Read more about these vulnerabilities, cases of their exploitation, and remediation methods in the digest.