Patch Tuesday Archive
Patch Tuesday September 2024
Total CVEs
86
Critical
9
Important
74
Exploited
5
Publicly Disclosed
2
All CVEs this month 86
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2024-37338 | Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | Important | 8.8 |
SQL Server | - | - | - |
| CVE-2024-37966 | Microsoft SQL Server Native Scoring Information Disclosure Vulnerability | Important | 7.1 |
SQL Server | - | - | - |
| CVE-2024-37335 | Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | Important | 8.8 |
SQL Server | - | - | - |
| CVE-2024-37340 | Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | Important | 8.8 |
SQL Server | - | - | - |
| CVE-2024-37339 | Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | Important | 8.8 |
SQL Server | - | - | - |
| CVE-2024-37337 | Microsoft SQL Server Native Scoring Information Disclosure Vulnerability | Important | 4.3 |
SQL Server | - | - | - |
| CVE-2024-37342 | Microsoft SQL Server Native Scoring Information Disclosure Vulnerability | Important | 4.3 |
SQL Server | - | - | - |
| CVE-2024-26186 | Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | Important | 8.8 |
SQL Server | - | - | - |
| CVE-2024-26191 | Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | Important | 8.8 |
SQL Server | - | - | - |
| CVE-2024-38018 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Critical | 8.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2024-38216 | Azure Stack Hub Elevation of Privilege Vulnerability | Critical | 9 |
Azure Stack | - | - | - |
| CVE-2024-38220 | Azure Stack Hub Elevation of Privilege Vulnerability | Critical | 9 |
Azure Stack | - | - | - |
| CVE-2024-38188 | Azure Network Watcher VM Agent Elevation of Privilege Vulnerability | Important | 7.1 |
Azure Network Watcher | - | - | - |
| CVE-2024-38230 | Windows Standards-Based Storage Management Service Denial of Service Vulnerability | Important | 7.5 |
Windows Standards-Based Storage Management Service | - | - | - |
| CVE-2024-38236 | DHCP Server Service Denial of Service Vulnerability | Important | 7.5 |
Windows DHCP Server | - | - | - |
| CVE-2024-38240 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | Important | 9.8 |
Windows Remote Access Connection Manager | - | - | - |
| CVE-2024-38241 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Streaming Service | - | - | - |
| CVE-2024-38242 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Streaming Service | - | - | - |
| CVE-2024-38249 | Windows Graphics Component Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2024-38250 | Windows Graphics Component Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2024-38252 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Win32K - ICOMP | - | - | - |
| CVE-2024-38253 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Win32K - ICOMP | - | - | - |
| CVE-2024-38254 | Windows Authentication Information Disclosure Vulnerability | Important | 6.2 |
Windows Authentication Methods | - | - | - |
| CVE-2024-38256 | Windows Kernel-Mode Driver Information Disclosure Vulnerability | Important | 5.5 |
Windows Kernel-Mode Drivers | - | - | - |
| CVE-2024-43463 | Microsoft Office Visio Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Visio | - | - | - |
| CVE-2024-43464 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Critical | 7.2 |
Microsoft Office SharePoint | - | - | - |
| CVE-2024-43467 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | Important | 7.5 |
Windows Remote Desktop Licensing Service | - | - | - |
| CVE-2024-43474 | Microsoft SQL Server Information Disclosure Vulnerability | Important | 7.5 |
SQL Server | - | - | - |
| CVE-2024-43482 | Microsoft Outlook for iOS Information Disclosure Vulnerability | Important | 6.5 |
Microsoft Outlook for iOS | - | - | - |
| CVE-2024-43492 | Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft AutoUpdate (MAU) | - | - | - |
| CVE-2024-43465 | Microsoft Excel Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2024-38221 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Moderate | 4.3 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2024-37965 | Microsoft SQL Server Elevation of Privilege Vulnerability | Important | 8.8 |
SQL Server | - | - | - |
| CVE-2024-37341 | Microsoft SQL Server Elevation of Privilege Vulnerability | Important | 9.8 |
SQL Server | - | - | - |
| CVE-2024-38014 | Windows Installer Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Installer | Yes | - | - |
| CVE-2024-38046 | PowerShell Elevation of Privilege Vulnerability | Important | 7.8 |
Windows PowerShell | - | - | - |
| CVE-2024-38217 | Windows Mark of the Web Security Feature Bypass Vulnerability | Important | 5.4 |
Windows Mark of the Web (MOTW) | Yes | Yes | - |
| CVE-2024-38225 | Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability | Important | 9.8 |
Dynamics Business Central | - | - | - |
| CVE-2024-38226 | Microsoft Publisher Security Feature Bypass Vulnerability | Important | 7.3 |
Microsoft Office Publisher | Yes | - | - |
| CVE-2024-38227 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important | 7.2 |
Microsoft Office SharePoint | - | - | - |
| CVE-2024-38228 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important | 7.2 |
Microsoft Office SharePoint | - | - | - |
| CVE-2024-38231 | Windows Remote Desktop Licensing Service Denial of Service Vulnerability | Important | 7.5 |
Windows Remote Desktop Licensing Service | - | - | - |
| CVE-2024-38232 | Windows Networking Denial of Service Vulnerability | Important | 7.5 |
Windows Network Virtualization | - | - | - |
| CVE-2024-38233 | Windows Networking Denial of Service Vulnerability | Important | 7.5 |
Windows Network Virtualization | - | - | - |
| CVE-2024-38234 | Windows Networking Denial of Service Vulnerability | Important | 6.5 |
Windows Network Virtualization | - | - | - |
| CVE-2024-38235 | Windows Hyper-V Denial of Service Vulnerability | Important | 6.5 |
Role: Windows Hyper-V | - | - | - |
| CVE-2024-38237 | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Streaming Service | - | - | - |
| CVE-2024-38238 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Streaming Service | - | - | - |
| CVE-2024-38239 | Windows Kerberos Elevation of Privilege Vulnerability | Important | 7.2 |
Windows Kerberos | - | - | - |
| CVE-2024-38243 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Streaming Service | - | - | - |
| CVE-2024-38244 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Streaming Service | - | - | - |
| CVE-2024-38245 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Streaming Service | - | - | - |
| CVE-2024-38246 | Win32k Elevation of Privilege Vulnerability | Important | 7 |
Windows Win32K - GRFX | - | - | - |
| CVE-2024-38247 | Windows Graphics Component Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2024-38248 | Windows Storage Elevation of Privilege Vulnerability | Important | 7 |
Windows Storage | - | - | - |
| CVE-2024-38257 | Microsoft AllJoyn API Information Disclosure Vulnerability | Important | 7.5 |
Windows AllJoyn API | - | - | - |
| CVE-2024-38258 | Windows Remote Desktop Licensing Service Information Disclosure Vulnerability | Important | 7.5 |
Windows Remote Desktop Licensing Service | - | - | - |
| CVE-2024-38259 | Microsoft Management Console Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Management Console | - | - | - |
| CVE-2024-38260 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Remote Desktop Licensing Service | - | - | - |
| CVE-2024-38263 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | Important | 7.5 |
Windows Remote Desktop Licensing Service | - | - | - |
| CVE-2024-21416 | Windows TCP/IP Remote Code Execution Vulnerability | Important | 9.8 |
Windows TCP/IP | - | - | - |
| CVE-2024-38045 | Windows TCP/IP Remote Code Execution Vulnerability | Important | 8.1 |
Windows TCP/IP | - | - | - |
| CVE-2024-38119 | Windows Network Address Translation (NAT) Remote Code Execution Vulnerability | Critical | 7.5 |
Windows Network Address Translation (NAT) | - | - | - |
| CVE-2024-43454 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | Important | 7.1 |
Windows Remote Desktop Licensing Service | - | - | - |
| CVE-2024-43455 | Windows Remote Desktop Licensing Service Spoofing Vulnerability | Important | 9.8 |
Windows Remote Desktop Licensing Service | - | - | - |
| CVE-2024-43457 | Windows Setup and Deployment Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Setup and Deployment | - | - | - |
| CVE-2024-43458 | Windows Networking Information Disclosure Vulnerability | Important | 7.7 |
Windows Network Virtualization | - | - | - |
| CVE-2024-43461 | Windows MSHTML Platform Spoofing Vulnerability | Important | 8.8 |
Windows MSHTML Platform | Yes | Yes | - |
| CVE-2024-43466 | Microsoft SharePoint Server Denial of Service Vulnerability | Important | 7.5 |
Microsoft Office SharePoint | - | - | - |
| CVE-2024-43469 | Azure CycleCloud Remote Code Execution Vulnerability | Important | 8.8 |
Azure CycleCloud | - | - | - |
| CVE-2024-43470 | Azure Network Watcher VM Agent Elevation of Privilege Vulnerability | Important | 7.3 |
Azure Network Watcher | - | - | - |
| CVE-2024-43475 | Microsoft Windows Admin Center Information Disclosure Vulnerability | Important | 7.3 |
Windows Admin Center | - | - | - |
| CVE-2024-43476 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Important | 5.4 |
Microsoft Dynamics 365 (on-premises) | - | - | - |
| CVE-2024-43479 | Microsoft Power Automate Desktop Remote Code Execution Vulnerability | Important | 8.5 |
Power Automate | - | - | - |
| CVE-2024-30073 | Windows Security Zone Mapping Security Feature Bypass Vulnerability | Important | 7.8 |
Windows Security Zone Mapping | - | - | - |
| CVE-2024-43487 | Windows Mark of the Web Security Feature Bypass Vulnerability | Moderate | 6.5 |
Windows Mark of the Web (MOTW) | - | - | - |
| CVE-2024-43491 | Microsoft Windows Update Remote Code Execution Vulnerability | Critical | 9.8 |
Windows Update | Yes | - | - |
| CVE-2024-43495 | Windows libarchive Remote Code Execution Vulnerability | Important | 7.3 |
Windows Libarchive | - | - | - |
| CVE-2024-38194 | Azure Web Apps Elevation of Privilege Vulnerability | Critical | 9.9 |
Azure Web Apps | - | - | - |
| CVE-2024-38222 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | Moderate | 6.5 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2024-38183 | GroupMe Elevation of Privilege Vulnerability | Critical | 9.8 |
GroupMe | - | - | - |
| CVE-2024-43460 | Dynamics 365 Business Central Elevation of Privilege Vulnerability | Critical | 8.8 |
Dynamics Business Central | - | - | - |
| CVE-2024-38016 | Microsoft Office Visio Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Visio | - | - | - |
| CVE-2024-43496 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2024-43489 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2024-37980 | Microsoft SQL Server Elevation of Privilege Vulnerability | Important | 9.8 |
SQL Server | - | - | - |
Threat Categories 6
| Threat Category | CVEs | Critical |
|---|---|---|
| Elevation of Privilege | 32 | 5 |
| Remote Code Execution | 26 | 4 |
| Information Disclosure | 12 | - |
| Denial of Service | 8 | - |
| Security Feature Bypass | 4 | - |
| Spoofing | 4 | - |
Affected Products 43
| Product | CVEs | Exploited |
|---|---|---|
| SQL Server | 13 | - |
| Microsoft Streaming Service | 7 | - |
| Windows Remote Desktop Licensing Service | 7 | - |
| Microsoft Office SharePoint | 5 | - |
| Microsoft Edge (Chromium-based) | 4 | - |
| Windows Network Virtualization | 4 | - |
| Microsoft Graphics Component | 3 | - |
| Azure Network Watcher | 2 | - |
| Azure Stack | 2 | - |
| Dynamics Business Central | 2 | - |
| Microsoft Office Visio | 2 | - |
| Windows Mark of the Web (MOTW) | 2 | 1 |
| Windows TCP/IP | 2 | - |
| Windows Win32K - ICOMP | 2 | - |
| Azure CycleCloud | 1 | - |
| Azure Web Apps | 1 | - |
| GroupMe | 1 | - |
| Microsoft AutoUpdate (MAU) | 1 | - |
| Microsoft Dynamics 365 (on-premises) | 1 | - |
| Microsoft Management Console | 1 | - |
| Microsoft Office Excel | 1 | - |
| Microsoft Office Publisher | 1 | 1 |
| Microsoft Outlook for iOS | 1 | - |
| Power Automate | 1 | - |
| Role: Windows Hyper-V | 1 | - |
| Windows Admin Center | 1 | - |
| Windows AllJoyn API | 1 | - |
| Windows Authentication Methods | 1 | - |
| Windows DHCP Server | 1 | - |
| Windows Installer | 1 | 1 |
| Windows Kerberos | 1 | - |
| Windows Kernel-Mode Drivers | 1 | - |
| Windows Libarchive | 1 | - |
| Windows MSHTML Platform | 1 | 1 |
| Windows Network Address Translation (NAT) | 1 | - |
| Windows PowerShell | 1 | - |
| Windows Remote Access Connection Manager | 1 | - |
| Windows Security Zone Mapping | 1 | - |
| Windows Setup and Deployment | 1 | - |
| Windows Standards-Based Storage Management Service | 1 | - |
| Windows Storage | 1 | - |
| Windows Update | 1 | 1 |
| Windows Win32K - GRFX | 1 | - |