Patch Tuesday Archive
Patch Tuesday March 2024
Total CVEs
66
Critical
2
Important
59
Exploited
0
Publicly Disclosed
1
All CVEs this month 66
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2024-21392 | .NET and Visual Studio Denial of Service Vulnerability | Important | 7.5 |
.NET | - | - | - |
| CVE-2024-21421 | Azure SDK Spoofing Vulnerability | Important | 7.5 |
Azure SDK | - | - | - |
| CVE-2024-20671 | Microsoft Defender Security Feature Bypass Vulnerability | Important | 5.5 |
Windows Defender | - | - | - |
| CVE-2024-21426 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2024-21429 | Windows USB Hub Driver Remote Code Execution Vulnerability | Important | 6.8 |
Windows USB Hub Driver | - | - | - |
| CVE-2024-21430 | Windows USB Attached SCSI (UAS) Protocol Remote Code Execution Vulnerability | Important | 6.4 |
Windows USB Serial Driver | - | - | - |
| CVE-2024-21438 | Microsoft AllJoyn API Denial of Service Vulnerability | Important | 7.5 |
Windows AllJoyn API | - | - | - |
| CVE-2024-21439 | Windows Telephony Server Elevation of Privilege Vulnerability | Important | 7 |
Windows Telephony Server | - | - | - |
| CVE-2024-21441 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft WDAC OLE DB provider for SQL | - | - | - |
| CVE-2024-21442 | Windows USB Print Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows USB Print Driver | - | - | - |
| CVE-2024-21443 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.3 |
Windows Kernel | - | - | - |
| CVE-2024-21444 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft WDAC OLE DB provider for SQL | - | - | - |
| CVE-2024-21445 | Windows USB Print Driver Elevation of Privilege Vulnerability | Important | 7 |
Windows USB Print Driver | - | - | - |
| CVE-2024-21446 | NTFS Elevation of Privilege Vulnerability | Important | 7.8 |
Windows NTFS | - | - | - |
| CVE-2024-21450 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft WDAC OLE DB provider for SQL | - | - | - |
| CVE-2024-21451 | Microsoft ODBC Driver Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft WDAC ODBC Driver | - | - | - |
| CVE-2024-26197 | Windows Standards-Based Storage Management Service Denial of Service Vulnerability | Important | 6.5 |
Windows Standards-Based Storage Management Service | - | - | - |
| CVE-2024-26159 | Microsoft ODBC Driver Remote Code Execution Vulnerability | Important | 8.8 |
Windows ODBC Driver | - | - | - |
| CVE-2024-21427 | Windows Kerberos Security Feature Bypass Vulnerability | Important | 7.5 |
Windows Kerberos | - | - | - |
| CVE-2024-26190 | Microsoft QUIC Denial of Service Vulnerability | Important | 7.5 |
Microsoft QUIC | - | - | - |
| CVE-2024-26198 | Microsoft Exchange Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Exchange Server | - | - | - |
| CVE-2024-26199 | Microsoft Office Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2024-26201 | Microsoft Intune Linux Agent Elevation of Privilege Vulnerability | Important | 6.6 |
Microsoft Intune | - | - | - |
| CVE-2024-26203 | Azure Data Studio Elevation of Privilege Vulnerability | Important | 7.3 |
Azure Data Studio | - | - | - |
| CVE-2024-26161 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft WDAC OLE DB provider for SQL | - | - | - |
| CVE-2024-26164 | Microsoft Django Backend for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Django Backend for SQL Server | - | - | - |
| CVE-2024-26246 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | Low | 3.9 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2024-26163 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | Low | 4.7 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2024-21407 | Windows Hyper-V Remote Code Execution Vulnerability | Critical | 8.1 |
Role: Windows Hyper-V | - | - | - |
| CVE-2024-21408 | Windows Hyper-V Denial of Service Vulnerability | Critical | 5.5 |
Role: Windows Hyper-V | - | - | - |
| CVE-2024-21400 | Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability | Important | 9 |
Microsoft Azure Kubernetes Service | - | - | - |
| CVE-2024-21390 | Microsoft Authenticator Elevation of Privilege Vulnerability | Important | 7.1 |
Microsoft Authenticator | - | - | - |
| CVE-2024-21419 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Important | 5.4 |
Microsoft Dynamics | - | - | - |
| CVE-2024-21330 | Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability | Important | 7.8 |
Open Management Infrastructure | - | - | - |
| CVE-2024-21334 | Open Management Infrastructure (OMI) Remote Code Execution Vulnerability | Important | 9.8 |
Open Management Infrastructure | - | - | - |
| CVE-2024-21418 | Software for Open Networking in the Cloud (SONiC) Elevation of Privilege Vulnerability | Important | 7.8 |
Software for Open Networking in the Cloud (SONiC) | - | - | - |
| CVE-2024-21431 | Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability | Important | 6.7 |
Windows Hypervisor-Protected Code Integrity | - | - | - |
| CVE-2024-21432 | Windows Update Stack Elevation of Privilege Vulnerability | Important | 7 |
Windows Update Stack | - | - | - |
| CVE-2024-21433 | Windows Print Spooler Elevation of Privilege Vulnerability | Important | 7 |
Windows Print Spooler Components | - | - | - |
| CVE-2024-21434 | Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows SCSI Class System File | - | - | - |
| CVE-2024-21435 | Windows OLE Remote Code Execution Vulnerability | Important | 8.8 |
Windows OLE | - | - | - |
| CVE-2024-21436 | Windows Installer Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Installer | - | - | - |
| CVE-2024-21437 | Windows Graphics Component Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2024-21440 | Microsoft ODBC Driver Remote Code Execution Vulnerability | Important | 8.8 |
Windows ODBC Driver | - | - | - |
| CVE-2024-21448 | Microsoft Teams for Android Information Disclosure Vulnerability | Important | 5 |
Microsoft Teams for Android | - | - | - |
| CVE-2024-26160 | Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability | Important | 5.5 |
Windows Cloud Files Mini Filter Driver | - | - | - |
| CVE-2024-26162 | Microsoft ODBC Driver Remote Code Execution Vulnerability | Important | 8.8 |
Windows ODBC Driver | - | - | - |
| CVE-2024-26166 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft WDAC OLE DB provider for SQL | - | - | - |
| CVE-2024-26169 | Windows Error Reporting Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Error Reporting | - | - | - |
| CVE-2024-26170 | Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Composite Image File System | - | - | - |
| CVE-2024-26173 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2024-26174 | Windows Kernel Information Disclosure Vulnerability | Important | 5.5 |
Windows Kernel | - | - | - |
| CVE-2024-26176 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2024-26177 | Windows Kernel Information Disclosure Vulnerability | Important | 5.5 |
Windows Kernel | - | - | - |
| CVE-2024-26178 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2024-26181 | Windows Kernel Denial of Service Vulnerability | Important | 5.5 |
Windows Kernel | - | - | - |
| CVE-2024-26182 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2024-26185 | Windows Compressed Folder Tampering Vulnerability | Important | 6.5 |
Windows Compressed Folder | - | - | - |
| CVE-2024-26204 | Outlook for Android Information Disclosure Vulnerability | Important | 7.5 |
Outlook for Android | - | - | - |
| CVE-2024-26165 | Visual Studio Code Elevation of Privilege Vulnerability | Important | 8.8 |
Visual Studio Code | - | - | - |
| CVE-2024-26167 | Microsoft Edge for Android Spoofing Vulnerability | Low | 4.3 |
Microsoft Edge for Android | - | - | - |
| CVE-2024-29057 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Low | 4.3 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2024-26247 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | Low | 4.7 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2024-29059 | .NET Framework Information Disclosure Vulnerability | Important | 7.5 |
.NET Framework | - | - | - |
| CVE-2024-21411 | Skype for Consumer Remote Code Execution Vulnerability | Important | 8.8 |
Skype for Consumer | - | - | - |
| CVE-2024-28916 | Unknown | Important | 8.8 |
XBox Crypto Graphic Services | - | Yes | - |
Threat Categories 7
| Threat Category | CVEs | Critical |
|---|---|---|
| Elevation of Privilege | 25 | - |
| Remote Code Execution | 18 | 1 |
| Denial of Service | 6 | 1 |
| Information Disclosure | 6 | - |
| Security Feature Bypass | 6 | - |
| Spoofing | 4 | - |
| Tampering | 1 | - |
Affected Products 47
| Product | CVEs | Exploited |
|---|---|---|
| Windows Kernel | 8 | - |
| Microsoft WDAC OLE DB provider for SQL | 5 | - |
| Microsoft Edge (Chromium-based) | 4 | - |
| Windows ODBC Driver | 3 | - |
| Open Management Infrastructure | 2 | - |
| Role: Windows Hyper-V | 2 | - |
| Windows USB Print Driver | 2 | - |
| .NET | 1 | - |
| .NET Framework | 1 | - |
| Azure Data Studio | 1 | - |
| Azure SDK | 1 | - |
| Microsoft Authenticator | 1 | - |
| Microsoft Azure Kubernetes Service | 1 | - |
| Microsoft Django Backend for SQL Server | 1 | - |
| Microsoft Dynamics | 1 | - |
| Microsoft Edge for Android | 1 | - |
| Microsoft Exchange Server | 1 | - |
| Microsoft Graphics Component | 1 | - |
| Microsoft Intune | 1 | - |
| Microsoft Office | 1 | - |
| Microsoft Office SharePoint | 1 | - |
| Microsoft QUIC | 1 | - |
| Microsoft Teams for Android | 1 | - |
| Microsoft WDAC ODBC Driver | 1 | - |
| Microsoft Windows SCSI Class System File | 1 | - |
| Outlook for Android | 1 | - |
| Skype for Consumer | 1 | - |
| Software for Open Networking in the Cloud (SONiC) | 1 | - |
| Visual Studio Code | 1 | - |
| Windows AllJoyn API | 1 | - |
| Windows Cloud Files Mini Filter Driver | 1 | - |
| Windows Composite Image File System | 1 | - |
| Windows Compressed Folder | 1 | - |
| Windows Defender | 1 | - |
| Windows Error Reporting | 1 | - |
| Windows Hypervisor-Protected Code Integrity | 1 | - |
| Windows Installer | 1 | - |
| Windows Kerberos | 1 | - |
| Windows NTFS | 1 | - |
| Windows OLE | 1 | - |
| Windows Print Spooler Components | 1 | - |
| Windows Standards-Based Storage Management Service | 1 | - |
| Windows Telephony Server | 1 | - |
| Windows USB Hub Driver | 1 | - |
| Windows USB Serial Driver | 1 | - |
| Windows Update Stack | 1 | - |
| XBox Crypto Graphic Services | 1 | - |