Patch Tuesday Archive
Patch Tuesday August 2024
Total CVEs
96
Critical
9
Important
82
Exploited
6
Publicly Disclosed
4
All CVEs this month 96
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2024-38108 | Azure Stack Hub Spoofing Vulnerability | Important | 9.3 |
Azure Stack | - | - | - |
| CVE-2024-38123 | Windows Bluetooth Driver Information Disclosure Vulnerability | Important | 4.4 |
Microsoft Bluetooth Driver | - | - | - |
| CVE-2024-38159 | Windows Network Virtualization Remote Code Execution Vulnerability | Critical | 9.1 |
Windows Network Virtualization | - | - | - |
| CVE-2024-38160 | Windows Network Virtualization Remote Code Execution Vulnerability | Critical | 9.1 |
Windows Network Virtualization | - | - | - |
| CVE-2024-38161 | Windows Mobile Broadband Driver Remote Code Execution Vulnerability | Important | 6.8 |
Windows Mobile Broadband | - | - | - |
| CVE-2024-38167 | .NET and Visual Studio Information Disclosure Vulnerability | Important | 6.5 |
.NET and Visual Studio | - | - | - |
| CVE-2024-38168 | .NET and Visual Studio Denial of Service Vulnerability | Important | 7.5 |
.NET and Visual Studio | - | - | - |
| CVE-2024-38172 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2024-38178 | Scripting Engine Memory Corruption Vulnerability | Important | 7.5 |
Windows Scripting | Yes | - | - |
| CVE-2024-38184 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel-Mode Drivers | - | - | - |
| CVE-2024-38191 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel-Mode Drivers | - | - | - |
| CVE-2024-38193 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Ancillary Function Driver for WinSock | Yes | - | Yes |
| CVE-2024-38196 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Common Log File System Driver | - | - | - |
| CVE-2024-38197 | Microsoft Teams for iOS Spoofing Vulnerability | Important | 6.5 |
Microsoft Teams | - | - | - |
| CVE-2024-38198 | Windows Print Spooler Elevation of Privilege Vulnerability | Important | 7.5 |
Windows Print Spooler Components | - | - | - |
| CVE-2024-38199 | Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability | Important | 9.8 |
Line Printer Daemon Service (LPD) | - | Yes | - |
| CVE-2024-38201 | Azure Stack Hub Elevation of Privilege Vulnerability | Important | 7 |
Azure Stack | - | - | - |
| CVE-2024-38213 | Windows Mark of the Web Security Feature Bypass Vulnerability | Moderate | 6.5 |
Windows Mark of the Web (MOTW) | Yes | - | - |
| CVE-2024-38209 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2024-43477 | Microsoft Entra ID Elevation of Privilege Vulnerability | Critical | 7.5 |
Entra ID | - | - | - |
| CVE-2024-21302 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability | Important | 6.7 |
Windows Secure Kernel Mode | - | Yes | - |
| CVE-2024-38084 | Microsoft OfficePlus Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2024-38063 | Windows TCP/IP Remote Code Execution Vulnerability | Critical | 9.8 |
Windows TCP/IP | - | - | - |
| CVE-2024-38098 | Azure Connected Machine Agent Elevation of Privilege Vulnerability | Important | 7.8 |
Azure Connected Machine Agent | - | - | - |
| CVE-2024-38106 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7 |
Windows Kernel | Yes | - | - |
| CVE-2024-38107 | Windows Power Dependency Coordinator Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Power Dependency Coordinator | Yes | - | - |
| CVE-2024-29995 | Windows Kerberos Elevation of Privilege Vulnerability | Important | 8.1 |
Windows Kerberos | - | - | - |
| CVE-2024-38114 | Windows IP Routing Management Snapin Remote Code Execution Vulnerability | Important | 8.8 |
Windows IP Routing Management Snapin | - | - | - |
| CVE-2024-38115 | Windows IP Routing Management Snapin Remote Code Execution Vulnerability | Important | 8.8 |
Windows IP Routing Management Snapin | - | - | - |
| CVE-2024-38116 | Windows IP Routing Management Snapin Remote Code Execution Vulnerability | Important | 8.8 |
Windows IP Routing Management Snapin | - | - | - |
| CVE-2024-38117 | NTFS Elevation of Privilege Vulnerability | Important | 7.8 |
Windows NTFS | - | - | - |
| CVE-2024-38118 | Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Local Security Authority Server (lsasrv) | - | - | - |
| CVE-2024-38121 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Important | 8.8 |
Windows Routing and Remote Access Service (RRAS) | - | - | - |
| CVE-2024-38122 | Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Local Security Authority Server (lsasrv) | - | - | - |
| CVE-2024-38125 | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Streaming Service | - | - | - |
| CVE-2024-38126 | Windows Network Address Translation (NAT) Denial of Service Vulnerability | Important | 7.5 |
Windows Network Address Translation (NAT) | - | - | - |
| CVE-2024-38127 | Windows Hyper-V Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2024-38128 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Important | 8.8 |
Windows Routing and Remote Access Service (RRAS) | - | - | - |
| CVE-2024-38130 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Important | 8.8 |
Windows Routing and Remote Access Service (RRAS) | - | - | - |
| CVE-2024-38131 | Clipboard Virtual Channel Extension Remote Code Execution Vulnerability | Important | 8.8 |
Windows Clipboard Virtual Channel Extension | - | - | - |
| CVE-2024-38132 | Windows Network Address Translation (NAT) Denial of Service Vulnerability | Important | 7.5 |
Windows Network Address Translation (NAT) | - | - | - |
| CVE-2024-38133 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2024-38134 | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Streaming Service | - | - | - |
| CVE-2024-38135 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | Important | 7.8 |
Windows NT OS Kernel | - | - | - |
| CVE-2024-38136 | Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability | Important | 7 |
Windows Resource Manager | - | - | - |
| CVE-2024-38137 | Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability | Important | 7 |
Windows Resource Manager | - | - | - |
| CVE-2024-38138 | Windows Deployment Services Remote Code Execution Vulnerability | Important | 7.5 |
Windows Deployment Services | - | - | - |
| CVE-2024-38140 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | Critical | 9.8 |
Reliable Multicast Transport Driver (RMCAST) | - | - | - |
| CVE-2024-38141 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Ancillary Function Driver for WinSock | - | - | - |
| CVE-2024-38142 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Secure Kernel Mode | - | - | - |
| CVE-2024-38143 | Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability | Important | 4.2 |
Windows WLAN Auto Config Service | - | - | - |
| CVE-2024-38144 | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | Important | 8.8 |
Microsoft Streaming Service | - | - | - |
| CVE-2024-38145 | Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability | Important | 7.5 |
Windows Layer-2 Bridge Network Driver | - | - | - |
| CVE-2024-38146 | Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability | Important | 7.5 |
Windows Layer-2 Bridge Network Driver | - | - | - |
| CVE-2024-38147 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | Important | 7.8 |
Windows DWM Core Library | - | - | - |
| CVE-2024-38148 | Windows Secure Channel Denial of Service Vulnerability | Important | 7.5 |
Windows Transport Security Layer (TLS) | - | - | - |
| CVE-2024-38150 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important | 7.8 |
Windows DWM Core Library | - | - | - |
| CVE-2024-38151 | Windows Kernel Information Disclosure Vulnerability | Important | 5.5 |
Windows Kernel | - | - | - |
| CVE-2024-38152 | Windows OLE Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft WDAC OLE DB provider for SQL | - | - | - |
| CVE-2024-38153 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2024-38154 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Important | 8.8 |
Windows Routing and Remote Access Service (RRAS) | - | - | - |
| CVE-2024-38155 | Security Center Broker Information Disclosure Vulnerability | Important | 5.5 |
Windows Security Center | - | - | - |
| CVE-2024-38157 | Azure IoT SDK Remote Code Execution Vulnerability | Important | 7 |
Azure IoT SDK | - | - | - |
| CVE-2024-38158 | Azure IoT SDK Remote Code Execution Vulnerability | Important | 7 |
Azure IoT SDK | - | - | - |
| CVE-2024-38162 | Azure Connected Machine Agent Elevation of Privilege Vulnerability | Important | 7.8 |
Azure Connected Machine Agent | - | - | - |
| CVE-2024-38165 | Windows Compressed Folder Tampering Vulnerability | Important | 6.5 |
Windows Compressed Folder | - | - | - |
| CVE-2024-38169 | Microsoft Office Visio Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Visio | - | - | - |
| CVE-2024-38170 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.1 |
Microsoft Office Excel | - | - | - |
| CVE-2024-38171 | Microsoft PowerPoint Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office PowerPoint | - | - | - |
| CVE-2024-38173 | Microsoft Outlook Remote Code Execution Vulnerability | Important | 6.7 |
Microsoft Office Outlook | - | - | - |
| CVE-2024-38177 | Windows App Installer Spoofing Vulnerability | Important | 7.8 |
Windows App Installer | - | - | - |
| CVE-2024-38180 | Windows SmartScreen Security Feature Bypass Vulnerability | Important | 8.8 |
Windows SmartScreen | - | - | - |
| CVE-2024-38185 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel-Mode Drivers | - | - | - |
| CVE-2024-38186 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel-Mode Drivers | - | - | - |
| CVE-2024-38187 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel-Mode Drivers | - | - | - |
| CVE-2024-38189 | Microsoft Project Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Office Project | Yes | - | - |
| CVE-2024-38195 | Azure CycleCloud Remote Code Execution Vulnerability | Important | 7.8 |
Azure CycleCloud | - | - | - |
| CVE-2024-38163 | Windows Update Stack Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Update Stack | - | - | - |
| CVE-2024-38200 | Microsoft Office Spoofing Vulnerability | Important | 6.5 |
Microsoft Office | - | Yes | - |
| CVE-2024-38211 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Important | 8.2 |
Microsoft Dynamics | - | - | - |
| CVE-2024-38120 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Important | 8.8 |
Windows Routing and Remote Access Service (RRAS) | - | - | - |
| CVE-2024-38214 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | Important | 6.5 |
Windows Routing and Remote Access Service (RRAS) | - | - | - |
| CVE-2024-38215 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Cloud Files Mini Filter Driver | - | - | - |
| CVE-2024-38166 | Microsoft Dynamics 365 Cross-site Scripting Vulnerability | Critical | 6.1 |
Microsoft Dynamics | - | - | - |
| CVE-2024-38206 | Microsoft Copilot Studio Information Disclosure Vulnerability | Critical | 6.5 |
Microsoft Copilot Studio | - | - | - |
| CVE-2024-38202 | Windows Update Stack Elevation of Privilege Vulnerability | Important | 7.3 |
Windows Update Stack | - | Yes | - |
| CVE-2024-38218 | Microsoft Edge (HTML-based) Memory Corruption Vulnerability | Important | 7.8 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2024-38219 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Moderate | 9 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2024-38223 | Windows Initial Machine Configuration Elevation of Privilege Vulnerability | Important | 6.8 |
Windows Initial Machine Configuration | - | - | - |
| CVE-2024-38109 | Azure Health Bot Elevation of Privilege Vulnerability | Critical | 8.8 |
Azure Health Bot | - | - | - |
| CVE-2024-38175 | Azure Managed Instance for Apache Cassandra Elevation of Privilege Vulnerability | Critical | 8.8 |
Azure Managed Instance for Apache Cassandra | - | - | - |
| CVE-2024-38208 | Microsoft Edge for Android Spoofing Vulnerability | Moderate | 6.1 |
Microsoft Edge for Android | - | - | - |
| CVE-2024-38207 | Microsoft Edge (HTML-based) Memory Corruption Vulnerability | Moderate | 6.3 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2024-38210 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2024-37968 | Windows DNS Spoofing Vulnerability | Important | 7.5 |
Microsoft Windows DNS | - | - | - |
| CVE-2024-43472 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Moderate | 8.3 |
Microsoft Edge (Chromium-based) | - | - | - |
Threat Categories 7
| Threat Category | CVEs | Critical |
|---|---|---|
| Elevation of Privilege | 39 | 3 |
| Remote Code Execution | 32 | 4 |
| Information Disclosure | 8 | 1 |
| Spoofing | 8 | 1 |
| Denial of Service | 6 | - |
| Security Feature Bypass | 2 | - |
| Tampering | 1 | - |
Affected Products 58
| Product | CVEs | Exploited |
|---|---|---|
| Microsoft Edge (Chromium-based) | 6 | - |
| Windows Routing and Remote Access Service (RRAS) | 6 | - |
| Windows Kernel | 5 | 1 |
| Windows Kernel-Mode Drivers | 5 | - |
| Microsoft Streaming Service | 3 | - |
| Windows IP Routing Management Snapin | 3 | - |
| .NET and Visual Studio | 2 | - |
| Azure Connected Machine Agent | 2 | - |
| Azure IoT SDK | 2 | - |
| Azure Stack | 2 | - |
| Microsoft Dynamics | 2 | - |
| Microsoft Local Security Authority Server (lsasrv) | 2 | - |
| Microsoft Office | 2 | - |
| Microsoft Office Excel | 2 | - |
| Windows Ancillary Function Driver for WinSock | 2 | 1 |
| Windows DWM Core Library | 2 | - |
| Windows Layer-2 Bridge Network Driver | 2 | - |
| Windows Network Address Translation (NAT) | 2 | - |
| Windows Network Virtualization | 2 | - |
| Windows Resource Manager | 2 | - |
| Windows Secure Kernel Mode | 2 | - |
| Windows Update Stack | 2 | - |
| Azure CycleCloud | 1 | - |
| Azure Health Bot | 1 | - |
| Azure Managed Instance for Apache Cassandra | 1 | - |
| Entra ID | 1 | - |
| Line Printer Daemon Service (LPD) | 1 | - |
| Microsoft Bluetooth Driver | 1 | - |
| Microsoft Copilot Studio | 1 | - |
| Microsoft Edge for Android | 1 | - |
| Microsoft Office Outlook | 1 | - |
| Microsoft Office PowerPoint | 1 | - |
| Microsoft Office Project | 1 | 1 |
| Microsoft Office Visio | 1 | - |
| Microsoft Teams | 1 | - |
| Microsoft WDAC OLE DB provider for SQL | 1 | - |
| Microsoft Windows DNS | 1 | - |
| Reliable Multicast Transport Driver (RMCAST) | 1 | - |
| Windows App Installer | 1 | - |
| Windows Clipboard Virtual Channel Extension | 1 | - |
| Windows Cloud Files Mini Filter Driver | 1 | - |
| Windows Common Log File System Driver | 1 | - |
| Windows Compressed Folder | 1 | - |
| Windows Deployment Services | 1 | - |
| Windows Initial Machine Configuration | 1 | - |
| Windows Kerberos | 1 | - |
| Windows Mark of the Web (MOTW) | 1 | 1 |
| Windows Mobile Broadband | 1 | - |
| Windows NT OS Kernel | 1 | - |
| Windows NTFS | 1 | - |
| Windows Power Dependency Coordinator | 1 | 1 |
| Windows Print Spooler Components | 1 | - |
| Windows Scripting | 1 | 1 |
| Windows Security Center | 1 | - |
| Windows SmartScreen | 1 | - |
| Windows TCP/IP | 1 | - |
| Windows Transport Security Layer (TLS) | 1 | - |
| Windows WLAN Auto Config Service | 1 | - |