Overview
- Microsoft's November Patch Tuesday addressed 91 security vulnerabilities, including four critical zero-day flaws.
- Two zero-day vulnerabilities, affecting Windows Task Scheduler and NTLM, are actively exploited in the wild.
- The most severe vulnerabilities include remote code execution issues in Azure CycleCloud and .NET, both with high CVSS scores.
- CISA added the Windows Task Scheduler and NTLMv2 issues to its Known Exploited Vulnerabilities Catalog.
- Other major vendors like Adobe, Cisco, and Citrix also released significant security updates this month.