Patch Tuesday Archive
Patch Tuesday January 2024
Total CVEs
57
Critical
2
Important
49
Exploited
0
Publicly Disclosed
0
All CVEs this month 57
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2024-20676 | Azure Storage Mover Remote Code Execution Vulnerability | Important | 8 |
Azure Storage Mover | - | - | - |
| CVE-2024-21337 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Moderate | 5.2 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2024-20674 | Windows Kerberos Security Feature Bypass Vulnerability | Critical | 8.8 |
Windows Authentication Methods | - | - | - |
| CVE-2024-20677 | Microsoft Office Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2024-20654 | Microsoft ODBC Driver Remote Code Execution Vulnerability | Important | 8 |
Windows ODBC Driver | - | - | - |
| CVE-2024-20657 | Windows Group Policy Elevation of Privilege Vulnerability | Important | 7 |
Windows Group Policy | - | - | - |
| CVE-2024-20658 | Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Virtual Hard Drive | - | - | - |
| CVE-2024-20680 | Windows Message Queuing Client (MSMQC) Information Disclosure | Important | 6.5 |
Windows Message Queuing | - | - | - |
| CVE-2024-20682 | Windows Cryptographic Services Remote Code Execution Vulnerability | Important | 7.8 |
Windows Cryptographic Services | - | - | - |
| CVE-2024-20683 | Win32k Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Win32K | - | - | - |
| CVE-2024-20690 | Windows Nearby Sharing Spoofing Vulnerability | Important | 6.5 |
Windows Nearby Sharing | - | - | - |
| CVE-2024-20691 | Windows Themes Information Disclosure Vulnerability | Important | 4.7 |
Windows Themes | - | - | - |
| CVE-2024-20694 | Windows CoreMessaging Information Disclosure Vulnerability | Important | 5.5 |
Windows Collaborative Translation Framework | - | - | - |
| CVE-2024-20696 | Windows libarchive Remote Code Execution Vulnerability | Important | 7.3 |
Windows Libarchive | - | - | - |
| CVE-2024-20697 | Windows libarchive Remote Code Execution Vulnerability | Important | 7.3 |
Windows Libarchive | - | - | - |
| CVE-2024-20698 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2024-20699 | Windows Hyper-V Denial of Service Vulnerability | Important | 5.5 |
Windows Hyper-V | - | - | - |
| CVE-2024-20700 | Windows Hyper-V Remote Code Execution Vulnerability | Critical | 7.5 |
Windows Hyper-V | - | - | - |
| CVE-2024-21305 | Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability | Important | 4.4 |
Unified Extensible Firmware Interface | - | - | - |
| CVE-2024-21307 | Remote Desktop Client Remote Code Execution Vulnerability | Important | 7.5 |
Remote Desktop Client | - | - | - |
| CVE-2024-21313 | Windows TCP/IP Information Disclosure Vulnerability | Important | 5.3 |
Windows TCP/IP | - | - | - |
| CVE-2024-21325 | Microsoft Printer Metadata Troubleshooter Tool Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Devices | - | - | - |
| CVE-2024-20675 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | Low | 6.3 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2024-21326 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Important | 9.6 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2024-21382 | Microsoft Edge for Android Information Disclosure Vulnerability | Moderate | 4.3 |
Microsoft Edge for Android | - | - | - |
| CVE-2024-21383 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Low | 3.3 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2024-21385 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Important | 8.3 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2024-21387 | Microsoft Edge for Android Spoofing Vulnerability | Moderate | 5.3 |
Microsoft Edge for Android | - | - | - |
| CVE-2024-21388 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Important | 6.5 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2024-0056 | Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability | Important | 8.7 |
SQL Server | - | - | - |
| CVE-2024-0057 | NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability | Important | 9.8 |
.NET and Visual Studio | - | - | - |
| CVE-2024-20652 | Windows HTML Platforms Security Feature Bypass Vulnerability | Important | 8.1 |
Windows Scripting | - | - | - |
| CVE-2024-20653 | Microsoft Common Log File System Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Common Log File System Driver | - | - | - |
| CVE-2024-20655 | Microsoft Online Certificate Status Protocol (OCSP) Remote Code Execution Vulnerability | Important | 6.6 |
Windows Online Certificate Status Protocol (OCSP) SnapIn | - | - | - |
| CVE-2024-20656 | Visual Studio Elevation of Privilege Vulnerability | Important | 7.8 |
Visual Studio | - | - | - |
| CVE-2024-20666 | BitLocker Security Feature Bypass Vulnerability | Important | 6.6 |
Windows BitLocker | - | - | - |
| CVE-2024-20660 | Microsoft Message Queuing Information Disclosure Vulnerability | Important | 6.5 |
Windows Message Queuing | - | - | - |
| CVE-2024-20661 | Microsoft Message Queuing Denial of Service Vulnerability | Important | 7.5 |
Windows Message Queuing | - | - | - |
| CVE-2024-20662 | Windows Online Certificate Status Protocol (OCSP) Information Disclosure Vulnerability | Important | 4.9 |
Windows Online Certificate Status Protocol (OCSP) SnapIn | - | - | - |
| CVE-2024-20663 | Windows Message Queuing Client (MSMQC) Information Disclosure | Important | 6.5 |
Windows Message Queuing | - | - | - |
| CVE-2024-20664 | Microsoft Message Queuing Information Disclosure Vulnerability | Important | 6.5 |
Windows Message Queuing | - | - | - |
| CVE-2024-21316 | Windows Server Key Distribution Service Security Feature Bypass | Important | 6.1 |
Windows Server Key Distribution Service | - | - | - |
| CVE-2024-20681 | Windows Subsystem for Linux Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Subsystem for Linux | - | - | - |
| CVE-2024-20686 | Win32k Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Win32 Kernel Subsystem | - | - | - |
| CVE-2024-20687 | Microsoft AllJoyn API Denial of Service Vulnerability | Important | 7.5 |
Windows AllJoyn API | - | - | - |
| CVE-2024-20692 | Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability | Important | 5.7 |
Windows Local Security Authority Subsystem Service (LSASS) | - | - | - |
| CVE-2024-21306 | Microsoft Bluetooth Driver Spoofing Vulnerability | Important | 5.7 |
Microsoft Bluetooth Driver | - | - | - |
| CVE-2024-21309 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel-Mode Drivers | - | - | - |
| CVE-2024-21310 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Cloud Files Mini Filter Driver | - | - | - |
| CVE-2024-21311 | Windows Cryptographic Services Information Disclosure Vulnerability | Important | 5.5 |
Windows Cryptographic Services | - | - | - |
| CVE-2024-21312 | .NET Framework Denial of Service Vulnerability | Important | 7.5 |
.NET Framework | - | - | - |
| CVE-2024-21314 | Microsoft Message Queuing Information Disclosure Vulnerability | Important | 6.5 |
Windows Message Queuing | - | - | - |
| CVE-2024-21318 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2024-21320 | Windows Themes Spoofing Vulnerability | Important | 6.5 |
Windows Themes | - | - | - |
| CVE-2024-21336 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Low | 2.5 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2024-20672 | .NET Denial of Service Vulnerability | Important | 7.5 |
.NET | - | - | - |
| CVE-2024-21319 | Microsoft Identity Denial of service vulnerability | Important | 6.8 |
Microsoft Identity Services | - | - | - |
Threat Categories 6
| Threat Category | CVEs | Critical |
|---|---|---|
| Elevation of Privilege | 14 | - |
| Information Disclosure | 12 | - |
| Remote Code Execution | 11 | 1 |
| Security Feature Bypass | 8 | 1 |
| Denial of Service | 6 | - |
| Spoofing | 6 | - |
Affected Products 40
| Product | CVEs | Exploited |
|---|---|---|
| Microsoft Edge (Chromium-based) | 7 | - |
| Windows Message Queuing | 6 | - |
| Microsoft Edge for Android | 2 | - |
| Windows Cryptographic Services | 2 | - |
| Windows Hyper-V | 2 | - |
| Windows Libarchive | 2 | - |
| Windows Online Certificate Status Protocol (OCSP) SnapIn | 2 | - |
| Windows Themes | 2 | - |
| .NET | 1 | - |
| .NET Framework | 1 | - |
| .NET and Visual Studio | 1 | - |
| Azure Storage Mover | 1 | - |
| Microsoft Bluetooth Driver | 1 | - |
| Microsoft Devices | 1 | - |
| Microsoft Identity Services | 1 | - |
| Microsoft Office | 1 | - |
| Microsoft Office SharePoint | 1 | - |
| Microsoft Virtual Hard Drive | 1 | - |
| Remote Desktop Client | 1 | - |
| SQL Server | 1 | - |
| Unified Extensible Firmware Interface | 1 | - |
| Visual Studio | 1 | - |
| Windows AllJoyn API | 1 | - |
| Windows Authentication Methods | 1 | - |
| Windows BitLocker | 1 | - |
| Windows Cloud Files Mini Filter Driver | 1 | - |
| Windows Collaborative Translation Framework | 1 | - |
| Windows Common Log File System Driver | 1 | - |
| Windows Group Policy | 1 | - |
| Windows Kernel | 1 | - |
| Windows Kernel-Mode Drivers | 1 | - |
| Windows Local Security Authority Subsystem Service (LSASS) | 1 | - |
| Windows Nearby Sharing | 1 | - |
| Windows ODBC Driver | 1 | - |
| Windows Scripting | 1 | - |
| Windows Server Key Distribution Service | 1 | - |
| Windows Subsystem for Linux | 1 | - |
| Windows TCP/IP | 1 | - |
| Windows Win32 Kernel Subsystem | 1 | - |
| Windows Win32K | 1 | - |