Microsoft addresses critical vulnerabilities in September 8 Patch Tuesday update
Microsoft's September 8 Patch Tuesday addressed two "Important" vulnerabilities, CVE-2024-21874 and CVE-2024-21875, which were actively exploited by attackers to gain elevated SYSTEM rights on Windowโฆ
Microsoft released its Septemberโฏ8 Patch Tuesday with two local elevationโofโprivilege flaws that attackers were already exploiting, and both were rated โImportantโ rather than โCritical.โ The vulnerabilities let a lowโprivilege user or process gain SYSTEM rights on Windows machines. Microsoftโs advisory urged immediate installation, warning that the bugs could let malware take full control of an infected host.
Patch Tuesday is the monthly cadence where Microsoft bundles security updates for its operating systems and applications. Historically, the companyโs severity labelsโCritical, Important, Moderate, Lowโhave guided administrators on which patches to prioritize. In this case, the two flaws, CVEโ2024โ21874 and CVEโ2024โ21875, affect the Windows kernel and the Win32k subsystem. Both were known to be weaponised in the wild before the bulletin, highlighting a gap between Microsoftโs rating and realโworld risk. Security experts have long argued that exploit activity, not just technical impact, should influence severity scores.
The CVEโ2024โ21874 bug allows an attacker with limited access to execute arbitrary code in kernel mode, while CVEโ2024โ21875 bypasses security checks in the graphics driver stack to elevate privileges. Together, they give a foothold that can be used to install ransomware, steal data, or move laterally across a network. Researchers from the cybersecurity community confirmed active exploitation in the wild, citing recent ransomware campaigns that leveraged these flaws. Microsoftโs patches address the code paths directly, and the updates are being rolled out through Windows Update, WSUS, and Microsoft Endpoint Manager.
Security teams are now racing to deploy the fixes before attackers can expand their foothold. Experts advise testing the patches in a controlled environment, then applying them across all Windows 10, Windows 11, and supported server versions within 24โฏhours. Microsoft says it will review its severityโrating methodology to better reflect active exploitation trends. For organizations, the episode underscores that โImportantโ does not mean โlow priorityโ when threat actors are already using the vulnerability. Prompt patching remains the most effective defense.
Read Full Story at VentureBeat โ


