September’s Patch Tuesday won’t require Microsoft users to rapidly repair rancid software, but SAP users need to move fast to address extremely dangerous bugs. Microsoft did find two bugs worthy of urgent attention. CVE-2025-55234 allows relay attacks and escalation of privileges against SMB Server. Admins can ameliorate these by using Server signing and the Extended Protection for Authentication (EPA) but it's better to patch and be safe than sorry. The second, CVE-2024-21907, isn't too much of an issue unless you're running a version of Newtonsoft.Json prior to the 13.0.1 build. This flaw emerged last year, so if you're vulnerable you may already face a problem with denial-of-service attacks exploiting the errors in its use of libraries. Microsoft’s fixed-flaw manifesto includes the 9.8-rated CVE-2025-55232 which can cause serious problems for users of Microsoft's High Performance Compute package, allowing code execution over the network. Redmond warns admins to watch for dodgy traffic on TCP port 5999 as that’s a sign this issue is under attack. That’s one of eight critical flaws. Office's Preview pane is still causing problems - this time with CVE-2025-54910. Maybe turn it off for the moment if possible. Redmond issued eight important patches for Excel. Six fixes for Defender Firewall address elevation of privilege attacks. Five fixes patch up Hyper-V. Users of Redmond’s Routing and Remote Access Service (RRAS) have ten fixes to consider. SAP NetWeaver customers need to g...
Microsoft closes 2024 with 72 fixes on final Patch Tuesday
The Register
·Iain Thomson
·Published Dec 10, 2024
·Updated
Affected Software
3 affected components
Microsoft SMB Server
Newtonsoft Json=13.0.1
Microsoft High Performance Compute
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses Microsoft's December 2024 Patch Tuesday, which includes 72 security fixes.
2
What security implications are discussed in the article?
The article highlights two critical vulnerabilities in Microsoft SMB Server that could lead to relay attacks and privilege escalation.
3
What products or software are affected by the vulnerabilities?
The affected products include Microsoft SMB Server and Microsoft High Performance Compute, as well as Newtonsoft Json.
4
What actions do users need to take to address the vulnerabilities?
Users of Microsoft SMB Server are urged to implement the patches promptly to mitigate the risks associated with the vulnerabilities.
5
Are there any urgent vulnerabilities mentioned for other software?
Yes, SAP users are advised to act quickly to address extremely dangerous bugs that are also mentioned in the article.