Microsoft's Biggest-Ever Security Update Fixes 974 Flaws, Two Already Used in Attacks

A record-breaking September patch release plugs two security holes that criminals were actively exploiting, plus 20 vulnerabilities serious enough that a single infected machine could spread the attack to others automatically.

ThreatVectr Newsdesk· 3 min read
A digital shield being breached by cyber threats
Share

Key points

  • Microsoft fixed 974 security vulnerabilities in its September 2024 update, the largest single patch release the company has ever issued.
  • Two of the flaws were zero-days, meaning Microsoft had no warning and criminals were already exploiting them before a fix existed.
  • Both zero-days allowed privilege escalation, where an attacker who is already inside a system secretly upgrades their own access to full administrator control.
  • Twenty of the patched vulnerabilities are rated potentially wormable, meaning malicious software could spread from machine to machine on its own, without anyone clicking anything.
  • Windows users, home and business, should apply the update immediately through Windows Update.

Microsoft released its monthly security update this September carrying 974 individual fixes. That is not a typo. SecurityWeek confirmed it is the highest number the company has ever shipped in a single batch.

To put that in plain terms: each fix addresses a specific crack in the wall of a Microsoft product, whether Windows, Office, or one of its cloud services. Finding and sealing 974 of those in one go is, to put it plainly, a lot.

Should ordinary users be worried?

Yes, but the fix is already available. The two most urgent flaws are the zero-days, and both involve privilege escalation. Think of it this way: a burglar finds a way in through a ground-floor window, then discovers a hidden master key that unlocks every room in the building. That is privilege escalation. Criminals were using both of these flaws in live attacks before Microsoft even knew the cracks existed.

The failure mode here is the gap between discovery and patching. During that window, no defence existed at the software level. Attackers who knew about these flaws could silently promote themselves from a limited account to a full system administrator, giving them control over everything on that machine.

What makes 20 of these flaws especially dangerous?

The wormable rating. A wormable vulnerability, meaning a flaw that lets malicious software copy and spread itself automatically across a network without any human help, is the kind of thing that turns one infected laptop into a hundred overnight. The 2017 WannaCry ransomware attack, which froze hospitals and businesses across more than 150 countries, was wormable. Twenty vulnerabilities carrying that potential in one update is not a number to brush past.

In practice, wormable flaws matter most inside large organisations: schools, hospitals, local councils, any place running many Windows machines on the same internal network. One unpatched device becomes the entry point for all of them.

Detail Figure
Total vulnerabilities patched 974
Zero-days actively exploited 2
Potentially wormable flaws 20
Patch release month September 2024
Vulnerability type (zero-days) Privilege escalation

One thing the post-mortem will say, if any organisation gets hit through one of these: the patch was available the day the news broke.

Home users: open Settings, go to Windows Update, and install everything waiting there. Business IT teams running Microsoft Endpoint Configuration Manager or Windows Server Update Services should already be in the queue. If you manage a fleet of Windows machines and you are not patching today, you are the wormable flaw.

Apply the update. That is the whole operational takeaway.

© 2026 Threat Vectr