Patch Tuesday Archive
Patch Tuesday February 2024
Total CVEs
77
Critical
5
Important
66
Exploited
4
Publicly Disclosed
0
All CVEs this month 77
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2024-20673 | Microsoft Office Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2024-21327 | Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability | Important | 7.6 |
Microsoft Dynamics | - | - | - |
| CVE-2024-21329 | Azure Connected Machine Agent Elevation of Privilege Vulnerability | Important | 7.3 |
Azure Connected Machine Agent | - | - | - |
| CVE-2024-21338 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | Yes | - | Yes |
| CVE-2024-20684 | Windows Hyper-V Denial of Service Vulnerability | Critical | 6.5 |
Windows Hyper-V | - | - | - |
| CVE-2024-21340 | Windows Kernel Information Disclosure Vulnerability | Important | 4.6 |
Windows Kernel | - | - | - |
| CVE-2024-21349 | Microsoft ActiveX Data Objects Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft ActiveX | - | - | - |
| CVE-2024-21350 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft WDAC OLE DB provider for SQL | - | - | - |
| CVE-2024-21351 | Windows SmartScreen Security Feature Bypass Vulnerability | Moderate | 7.6 |
Windows SmartScreen | Yes | - | - |
| CVE-2024-21352 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft WDAC OLE DB provider for SQL | - | - | - |
| CVE-2024-21354 | Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Message Queuing | - | - | - |
| CVE-2024-21357 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Internet Connection Sharing (ICS) | - | - | - |
| CVE-2024-21358 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft WDAC OLE DB provider for SQL | - | - | - |
| CVE-2024-21360 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft WDAC OLE DB provider for SQL | - | - | - |
| CVE-2024-21361 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft WDAC OLE DB provider for SQL | - | - | - |
| CVE-2024-21366 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft WDAC OLE DB provider for SQL | - | - | - |
| CVE-2024-21369 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft WDAC OLE DB provider for SQL | - | - | - |
| CVE-2024-21371 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7 |
Windows Kernel | - | - | - |
| CVE-2024-21372 | Windows OLE Remote Code Execution Vulnerability | Important | 8.8 |
Windows OLE | - | - | - |
| CVE-2024-21375 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft WDAC OLE DB provider for SQL | - | - | - |
| CVE-2024-21379 | Microsoft Word Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Word | - | - | - |
| CVE-2024-21381 | Microsoft Azure Active Directory B2C Spoofing Vulnerability | Important | 6.8 |
Azure Active Directory | - | - | - |
| CVE-2024-21386 | .NET Denial of Service Vulnerability | Important | 7.5 |
.NET | - | - | - |
| CVE-2024-21389 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Important | 7.6 |
Microsoft Dynamics | - | - | - |
| CVE-2024-21393 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Important | 7.6 |
Microsoft Dynamics | - | - | - |
| CVE-2024-21394 | Dynamics 365 Field Service Spoofing Vulnerability | Important | 7.6 |
Microsoft Dynamics | - | - | - |
| CVE-2024-21396 | Dynamics 365 Sales Spoofing Vulnerability | Important | 7.6 |
Microsoft Dynamics | - | - | - |
| CVE-2024-21401 | Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability | Important | 9.8 |
Azure Active Directory | - | - | - |
| CVE-2024-21402 | Microsoft Outlook Elevation of Privilege Vulnerability | Important | 7.1 |
Microsoft Office Outlook | - | - | - |
| CVE-2024-21404 | .NET Denial of Service Vulnerability | Important | 7.5 |
.NET | - | - | - |
| CVE-2024-21410 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Critical | 9.8 |
Microsoft Exchange Server | Yes | - | - |
| CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability | Critical | 9.8 |
Microsoft Office | - | - | - |
| CVE-2024-21420 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft WDAC OLE DB provider for SQL | - | - | - |
| CVE-2024-21423 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | Low | 4.8 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2024-26188 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Low | 4.3 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2024-26192 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | Important | 8.2 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2024-26196 | Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability | Low | 4.3 |
Microsoft Edge for Android | - | - | - |
| CVE-2024-21315 | Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Defender for Endpoint | - | - | - |
| CVE-2024-20695 | Skype for Business Information Disclosure Vulnerability | Important | 5.7 |
Skype for Business | - | - | - |
| CVE-2024-21304 | Trusted Compute Base Elevation of Privilege Vulnerability | Important | 4.1 |
Trusted Compute Base | - | - | - |
| CVE-2024-20667 | Azure DevOps Server Remote Code Execution Vulnerability | Important | 7.5 |
Azure DevOps | - | - | - |
| CVE-2024-20679 | Azure Stack Hub Spoofing Vulnerability | Important | 6.5 |
Azure Stack | - | - | - |
| CVE-2024-21328 | Dynamics 365 Sales Spoofing Vulnerability | Important | 7.6 |
Microsoft Dynamics | - | - | - |
| CVE-2024-21339 | Windows USB Generic Parent Driver Remote Code Execution Vulnerability | Important | 6.4 |
Windows USB Serial Driver | - | - | - |
| CVE-2024-21341 | Windows Kernel Remote Code Execution Vulnerability | Important | 6.8 |
Windows Kernel | - | - | - |
| CVE-2024-21342 | Windows DNS Client Denial of Service Vulnerability | Important | 7.5 |
Role: DNS Server | - | - | - |
| CVE-2024-21343 | Windows Network Address Translation (NAT) Denial of Service Vulnerability | Important | 7.5 |
Windows Internet Connection Sharing (ICS) | - | - | - |
| CVE-2024-21344 | Windows Network Address Translation (NAT) Denial of Service Vulnerability | Important | 5.9 |
Windows Internet Connection Sharing (ICS) | - | - | - |
| CVE-2024-21345 | Windows Kernel Elevation of Privilege Vulnerability | Important | 8.8 |
Windows Kernel | - | - | - |
| CVE-2024-21346 | Win32k Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Win32K - ICOMP | - | - | - |
| CVE-2024-21347 | Microsoft ODBC Driver Remote Code Execution Vulnerability | Important | 7.5 |
SQL Server | - | - | - |
| CVE-2024-21348 | Internet Connection Sharing (ICS) Denial of Service Vulnerability | Important | 7.5 |
Windows Internet Connection Sharing (ICS) | - | - | - |
| CVE-2024-21353 | Microsoft WDAC ODBC Driver Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft WDAC ODBC Driver | - | - | - |
| CVE-2024-21355 | Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability | Important | 7 |
Windows Message Queuing | - | - | - |
| CVE-2024-21356 | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | Important | 6.5 |
Windows LDAP - Lightweight Directory Access Protocol | - | - | - |
| CVE-2024-21359 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft WDAC OLE DB provider for SQL | - | - | - |
| CVE-2024-21362 | Windows Kernel Security Feature Bypass Vulnerability | Important | 5.5 |
Windows Kernel | - | - | - |
| CVE-2024-21363 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Important | 7.8 |
Windows Message Queuing | - | - | - |
| CVE-2024-21364 | Microsoft Azure Site Recovery Elevation of Privilege Vulnerability | Moderate | 9.3 |
Azure Site Recovery | - | - | - |
| CVE-2024-21365 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft WDAC OLE DB provider for SQL | - | - | - |
| CVE-2024-21367 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft WDAC OLE DB provider for SQL | - | - | - |
| CVE-2024-21368 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft WDAC OLE DB provider for SQL | - | - | - |
| CVE-2024-21370 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft WDAC OLE DB provider for SQL | - | - | - |
| CVE-2024-21374 | Microsoft Teams for Android Information Disclosure Vulnerability | Important | 5 |
Microsoft Teams for Android | - | - | - |
| CVE-2024-21376 | Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability | Important | 9 |
Microsoft Azure Kubernetes Service | - | - | - |
| CVE-2024-21377 | Windows DNS Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Windows DNS | - | - | - |
| CVE-2024-21378 | Microsoft Outlook Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Office Outlook | - | - | - |
| CVE-2024-21380 | Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability | Critical | 8 |
Microsoft Dynamics | - | - | - |
| CVE-2024-21384 | Microsoft Office OneNote Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office OneNote | - | - | - |
| CVE-2024-21391 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft WDAC OLE DB provider for SQL | - | - | - |
| CVE-2024-21395 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Important | 8.2 |
Microsoft Dynamics | - | - | - |
| CVE-2024-21397 | Microsoft Azure File Sync Elevation of Privilege Vulnerability | Important | 5.3 |
Azure File Sync | - | - | - |
| CVE-2024-21399 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Moderate | 8.3 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2024-21403 | Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability | Important | 9 |
Microsoft Azure Kubernetes Service | - | - | - |
| CVE-2024-21405 | Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability | Important | 7 |
Windows Message Queuing | - | - | - |
| CVE-2024-21406 | Windows Printing Service Spoofing Vulnerability | Important | 7.5 |
Microsoft Windows | - | - | - |
| CVE-2024-21412 | Internet Shortcut Files Security Feature Bypass Vulnerability | Important | 8.1 |
Internet Shortcut Files | Yes | - | - |
Threat Categories 6
| Threat Category | CVEs | Critical |
|---|---|---|
| Remote Code Execution | 31 | 2 |
| Elevation of Privilege | 16 | 1 |
| Spoofing | 11 | - |
| Denial of Service | 8 | 1 |
| Information Disclosure | 8 | 1 |
| Security Feature Bypass | 3 | - |
Affected Products 37
| Product | CVEs | Exploited |
|---|---|---|
| Microsoft WDAC OLE DB provider for SQL | 15 | - |
| Microsoft Dynamics | 8 | - |
| Windows Kernel | 6 | 1 |
| Microsoft Edge (Chromium-based) | 4 | - |
| Windows Internet Connection Sharing (ICS) | 4 | - |
| Windows Message Queuing | 4 | - |
| .NET | 2 | - |
| Azure Active Directory | 2 | - |
| Microsoft Azure Kubernetes Service | 2 | - |
| Microsoft Office | 2 | - |
| Microsoft Office Outlook | 2 | - |
| Azure Connected Machine Agent | 1 | - |
| Azure DevOps | 1 | - |
| Azure File Sync | 1 | - |
| Azure Site Recovery | 1 | - |
| Azure Stack | 1 | - |
| Internet Shortcut Files | 1 | 1 |
| Microsoft ActiveX | 1 | - |
| Microsoft Defender for Endpoint | 1 | - |
| Microsoft Edge for Android | 1 | - |
| Microsoft Exchange Server | 1 | 1 |
| Microsoft Office OneNote | 1 | - |
| Microsoft Office Word | 1 | - |
| Microsoft Teams for Android | 1 | - |
| Microsoft WDAC ODBC Driver | 1 | - |
| Microsoft Windows | 1 | - |
| Microsoft Windows DNS | 1 | - |
| Role: DNS Server | 1 | - |
| SQL Server | 1 | - |
| Skype for Business | 1 | - |
| Trusted Compute Base | 1 | - |
| Windows Hyper-V | 1 | - |
| Windows LDAP - Lightweight Directory Access Protocol | 1 | - |
| Windows OLE | 1 | - |
| Windows SmartScreen | 1 | 1 |
| Windows USB Serial Driver | 1 | - |
| Windows Win32K - ICOMP | 1 | - |