Patch Tuesday Archive
Patch Tuesday October 2024
Total CVEs
118
Critical
3
Important
113
Exploited
2
Publicly Disclosed
4
All CVEs this month 118
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2024-38097 | Azure Monitor Agent Elevation of Privilege Vulnerability | Important | 7.1 |
Azure Monitor | - | - | - |
| CVE-2024-43516 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Secure Kernel Mode | - | - | - |
| CVE-2024-38179 | Azure Stack Hyperconverged Infrastructure (HCI) Elevation of Privilege Vulnerability | Important | 8.8 |
Azure Stack | - | - | - |
| CVE-2024-38261 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Important | 7.8 |
Windows Routing and Remote Access Service (RRAS) | - | - | - |
| CVE-2024-43480 | Azure Service Fabric for Linux Remote Code Execution Vulnerability | Important | 6.6 |
Service Fabric | - | - | - |
| CVE-2024-43481 | Power BI Report Server Spoofing Vulnerability | Important | 8.8 |
Power BI | - | - | - |
| CVE-2024-38229 | .NET and Visual Studio Remote Code Execution Vulnerability | Important | 8.1 |
.NET and Visual Studio | - | - | - |
| CVE-2024-43502 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.1 |
Windows Kernel | - | - | - |
| CVE-2024-43503 | Microsoft SharePoint Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2024-43504 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2024-43505 | Microsoft Office Visio Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Visio | - | - | - |
| CVE-2024-43506 | BranchCache Denial of Service Vulnerability | Important | 7.5 |
BranchCache | - | - | - |
| CVE-2024-43508 | Windows Graphics Component Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Graphics Component | - | - | - |
| CVE-2024-43513 | BitLocker Security Feature Bypass Vulnerability | Important | 6.4 |
Windows BitLocker | - | - | - |
| CVE-2024-43515 | Internet Small Computer Systems Interface (iSCSI) Denial of Service Vulnerability | Important | 7.5 |
Internet Small Computer Systems Interface (iSCSI) | - | - | - |
| CVE-2024-43518 | Windows Telephony Server Remote Code Execution Vulnerability | Important | 8.8 |
Windows Telephony Server | - | - | - |
| CVE-2024-43519 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft WDAC OLE DB provider for SQL | - | - | - |
| CVE-2024-43525 | Windows Mobile Broadband Driver Remote Code Execution Vulnerability | Important | 6.8 |
Windows Mobile Broadband | - | - | - |
| CVE-2024-43526 | Windows Mobile Broadband Driver Remote Code Execution Vulnerability | Important | 6.8 |
Windows Mobile Broadband | - | - | - |
| CVE-2024-43527 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2024-43529 | Windows Print Spooler Elevation of Privilege Vulnerability | Important | 7.3 |
Windows Print Spooler Components | - | - | - |
| CVE-2024-43532 | Remote Registry Service Elevation of Privilege Vulnerability | Important | 8.8 |
RPC Endpoint Mapper Service | - | - | - |
| CVE-2024-43533 | Remote Desktop Client Remote Code Execution Vulnerability | Important | 8.8 |
Remote Desktop Client | - | - | - |
| CVE-2024-43534 | Windows Graphics Component Information Disclosure Vulnerability | Important | 6.5 |
Microsoft Graphics Component | - | - | - |
| CVE-2024-43535 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | Important | 7 |
Windows Kernel-Mode Drivers | - | - | - |
| CVE-2024-43537 | Windows Mobile Broadband Driver Denial of Service Vulnerability | Important | 6.5 |
Windows Mobile Broadband | - | - | - |
| CVE-2024-43538 | Windows Mobile Broadband Driver Denial of Service Vulnerability | Important | 6.5 |
Windows Mobile Broadband | - | - | - |
| CVE-2024-43540 | Windows Mobile Broadband Driver Denial of Service Vulnerability | Important | 6.5 |
Windows Mobile Broadband | - | - | - |
| CVE-2024-43541 | Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability | Important | 7.5 |
Microsoft Simple Certificate Enrollment Protocol | - | - | - |
| CVE-2024-43542 | Windows Mobile Broadband Driver Denial of Service Vulnerability | Important | 6.5 |
Windows Mobile Broadband | - | - | - |
| CVE-2024-43543 | Windows Mobile Broadband Driver Remote Code Execution Vulnerability | Important | 6.8 |
Windows Mobile Broadband | - | - | - |
| CVE-2024-43554 | Windows Kernel-Mode Driver Information Disclosure Vulnerability | Important | 5.5 |
Windows Kernel-Mode Drivers | - | - | - |
| CVE-2024-43573 | Windows MSHTML Platform Spoofing Vulnerability | Moderate | 8.1 |
Windows MSHTML Platform | Yes | Yes | - |
| CVE-2024-43576 | Microsoft Office Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2024-43581 | Microsoft OpenSSH for Windows Remote Code Execution Vulnerability | Important | 7.1 |
OpenSSH for Windows | - | - | - |
| CVE-2024-43601 | Visual Studio Code for Linux Remote Code Execution Vulnerability | Important | 7.8 |
Visual Studio Code | - | - | - |
| CVE-2024-43604 | Outlook for Android Elevation of Privilege Vulnerability | Important | 8 |
Outlook for Android | - | - | - |
| CVE-2024-43608 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Important | 8.8 |
Windows Routing and Remote Access Service (RRAS) | - | - | - |
| CVE-2024-43609 | Microsoft Office Spoofing Vulnerability | Important | 6.5 |
Microsoft Office | - | - | - |
| CVE-2024-43607 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Important | 8.8 |
Windows Routing and Remote Access Service (RRAS) | - | - | - |
| CVE-2024-43612 | Power BI Report Server Spoofing Vulnerability | Important | 4.7 |
Power BI | - | - | - |
| CVE-2024-43615 | Microsoft OpenSSH for Windows Remote Code Execution Vulnerability | Important | 7.1 |
OpenSSH for Windows | - | - | - |
| CVE-2024-43616 | Microsoft Office Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2024-43500 | Windows Resilient File System (ReFS) Information Disclosure Vulnerability | Important | 5.5 |
Windows Resilient File System (ReFS) | - | - | - |
| CVE-2024-20659 | Windows Hyper-V Security Feature Bypass Vulnerability | Important | 7.1 |
Role: Windows Hyper-V | - | Yes | - |
| CVE-2024-37976 | Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability | Important | 6.7 |
Windows EFI Partition | - | - | - |
| CVE-2024-37982 | Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability | Important | 7.8 |
Windows EFI Partition | - | - | - |
| CVE-2024-37979 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2024-37983 | Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability | Important | 6.7 |
Windows EFI Partition | - | - | - |
| CVE-2024-38149 | BranchCache Denial of Service Vulnerability | Important | 7.5 |
BranchCache | - | - | - |
| CVE-2024-38029 | Microsoft OpenSSH for Windows Remote Code Execution Vulnerability | Important | 7.5 |
OpenSSH for Windows | - | - | - |
| CVE-2024-38129 | Windows Kerberos Elevation of Privilege Vulnerability | Important | 6.6 |
Windows Kerberos | - | - | - |
| CVE-2024-38124 | Windows Netlogon Elevation of Privilege Vulnerability | Important | 9 |
Windows Netlogon | - | - | - |
| CVE-2024-38265 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Important | 8.8 |
Windows Routing and Remote Access Service (RRAS) | - | - | - |
| CVE-2024-38262 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | Important | 7.5 |
Windows Remote Desktop Licensing Service | - | - | - |
| CVE-2024-43453 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Important | 8.8 |
Windows Routing and Remote Access Service (RRAS) | - | - | - |
| CVE-2024-38212 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Important | 8.8 |
Windows Routing and Remote Access Service (RRAS) | - | - | - |
| CVE-2024-30092 | Windows Hyper-V Remote Code Execution Vulnerability | Important | 7.5 |
Windows Hyper-V | - | - | - |
| CVE-2024-43456 | Windows Remote Desktop Services Tampering Vulnerability | Important | 7.4 |
Windows Remote Desktop Services | - | - | - |
| CVE-2024-43483 | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | Important | 7.5 |
.NET, .NET Framework, Visual Studio | - | - | - |
| CVE-2024-43484 | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | Important | 7.5 |
.NET, .NET Framework, Visual Studio | - | - | - |
| CVE-2024-43485 | .NET and Visual Studio Denial of Service Vulnerability | Important | 7.5 |
.NET and Visual Studio | - | - | - |
| CVE-2024-43497 | DeepSpeed Remote Code Execution Vulnerability | Important | 7.8 |
DeepSpeed | - | - | - |
| CVE-2024-43468 | Microsoft Configuration Manager Remote Code Execution Vulnerability | Critical | 9.8 |
Microsoft Configuration Manager | - | - | - |
| CVE-2024-43501 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Common Log File System Driver | - | - | - |
| CVE-2024-43509 | Windows Graphics Component Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2024-43511 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7 |
Windows Kernel | - | - | - |
| CVE-2024-43512 | Windows Standards-Based Storage Management Service Denial of Service Vulnerability | Important | 7.5 |
Windows Standards-Based Storage Management Service | - | - | - |
| CVE-2024-43514 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | Important | 7.8 |
Windows NTFS | - | - | - |
| CVE-2024-43517 | Microsoft ActiveX Data Objects Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft ActiveX | - | - | - |
| CVE-2024-43520 | Windows Kernel Denial of Service Vulnerability | Important | 5 |
Windows Kernel | - | - | - |
| CVE-2024-43521 | Windows Hyper-V Denial of Service Vulnerability | Important | 7.5 |
Role: Windows Hyper-V | - | - | - |
| CVE-2024-43522 | Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability | Important | 7 |
Windows Local Security Authority (LSA) | - | - | - |
| CVE-2024-43523 | Windows Mobile Broadband Driver Remote Code Execution Vulnerability | Important | 6.8 |
Windows Mobile Broadband | - | - | - |
| CVE-2024-43524 | Windows Mobile Broadband Driver Remote Code Execution Vulnerability | Important | 6.8 |
Windows Mobile Broadband | - | - | - |
| CVE-2024-43528 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Secure Kernel Mode | - | - | - |
| CVE-2024-43536 | Windows Mobile Broadband Driver Remote Code Execution Vulnerability | Important | 6.8 |
Windows Mobile Broadband | - | - | - |
| CVE-2024-43544 | Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability | Important | 7.5 |
Microsoft Simple Certificate Enrollment Protocol | - | - | - |
| CVE-2024-43545 | Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability | Important | 7.5 |
Windows Online Certificate Status Protocol (OCSP) | - | - | - |
| CVE-2024-43546 | Windows Cryptographic Information Disclosure Vulnerability | Important | 5.6 |
Windows Cryptographic Services | - | - | - |
| CVE-2024-43547 | Windows Kerberos Information Disclosure Vulnerability | Important | 5.9 |
Windows Kerberos | - | - | - |
| CVE-2024-43549 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Important | 8.8 |
Windows Routing and Remote Access Service (RRAS) | - | - | - |
| CVE-2024-43550 | Windows Secure Channel Spoofing Vulnerability | Important | 7.4 |
Windows Secure Channel | - | - | - |
| CVE-2024-43551 | Windows Storage Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Storage | - | - | - |
| CVE-2024-43552 | Windows Shell Remote Code Execution Vulnerability | Important | 7.3 |
Windows Shell | - | - | - |
| CVE-2024-43553 | NT OS Kernel Elevation of Privilege Vulnerability | Important | 7 |
Windows NT OS Kernel | - | - | - |
| CVE-2024-43555 | Windows Mobile Broadband Driver Denial of Service Vulnerability | Important | 6.5 |
Windows Mobile Broadband | - | - | - |
| CVE-2024-43556 | Windows Graphics Component Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2024-43557 | Windows Mobile Broadband Driver Denial of Service Vulnerability | Important | 6.5 |
Windows Mobile Broadband | - | - | - |
| CVE-2024-43558 | Windows Mobile Broadband Driver Denial of Service Vulnerability | Important | 6.5 |
Windows Mobile Broadband | - | - | - |
| CVE-2024-43559 | Windows Mobile Broadband Driver Denial of Service Vulnerability | Important | 6.5 |
Windows Mobile Broadband | - | - | - |
| CVE-2024-43560 | Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Storage Port Driver | - | - | - |
| CVE-2024-43561 | Windows Mobile Broadband Driver Denial of Service Vulnerability | Important | 6.5 |
Windows Mobile Broadband | - | - | - |
| CVE-2024-43562 | Windows Network Address Translation (NAT) Denial of Service Vulnerability | Important | 7.5 |
Windows Network Address Translation (NAT) | - | - | - |
| CVE-2024-43563 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Ancillary Function Driver for WinSock | - | - | - |
| CVE-2024-43564 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Important | 8.8 |
Windows Routing and Remote Access Service (RRAS) | - | - | - |
| CVE-2024-43565 | Windows Network Address Translation (NAT) Denial of Service Vulnerability | Important | 7.5 |
Windows Network Address Translation (NAT) | - | - | - |
| CVE-2024-43567 | Windows Hyper-V Denial of Service Vulnerability | Important | 7.5 |
Role: Windows Hyper-V | - | - | - |
| CVE-2024-43570 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7 |
Windows Kernel | - | - | - |
| CVE-2024-43571 | Sudo for Windows Spoofing Vulnerability | Important | 7.3 |
Sudo for Windows | - | - | - |
| CVE-2024-43572 | Microsoft Management Console Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Management Console | Yes | Yes | - |
| CVE-2024-43574 | Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability | Important | 8.3 |
Microsoft Windows Speech | - | - | - |
| CVE-2024-43575 | Windows Hyper-V Denial of Service Vulnerability | Important | 7.5 |
Role: Windows Hyper-V | - | - | - |
| CVE-2024-43582 | Remote Desktop Protocol Server Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Remote Desktop | - | - | - |
| CVE-2024-43584 | Windows Scripting Engine Security Feature Bypass Vulnerability | Important | 8.4 |
Windows Scripting | - | - | - |
| CVE-2024-43585 | Code Integrity Guard Security Feature Bypass Vulnerability | Important | 5.5 |
Code Integrity Guard | - | - | - |
| CVE-2024-43589 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Important | 8.8 |
Windows Routing and Remote Access Service (RRAS) | - | - | - |
| CVE-2024-43590 | Visual C++ Redistributable Installer Elevation of Privilege Vulnerability | Important | 7.8 |
Visual C++ Redistributable Installer | - | - | - |
| CVE-2024-43591 | Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability | Important | 9.1 |
Azure CLI | - | - | - |
| CVE-2024-43592 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Important | 8.8 |
Windows Routing and Remote Access Service (RRAS) | - | - | - |
| CVE-2024-43593 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Important | 8.8 |
Windows Routing and Remote Access Service (RRAS) | - | - | - |
| CVE-2024-43599 | Remote Desktop Client Remote Code Execution Vulnerability | Important | 8.8 |
Remote Desktop Client | - | - | - |
| CVE-2024-43603 | Visual Studio Collector Service Denial of Service Vulnerability | Important | 5.5 |
Visual Studio | - | - | - |
| CVE-2024-43583 | Winlogon Elevation of Privilege Vulnerability | Important | 7.8 |
Winlogon | - | Yes | - |
| CVE-2024-43614 | Microsoft Defender for Endpoint for Linux Spoofing Vulnerability | Important | 5.5 |
Microsoft Defender for Endpoint | - | - | - |
| CVE-2024-43610 | Copilot Studio Information Disclosure Vulnerability | Unknown | 7.5 |
Copilot Studio | - | - | - |
| CVE-2024-43611 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Important | 8.8 |
Windows Routing and Remote Access Service (RRAS) | - | - | - |
| CVE-2024-43488 | Visual Studio Code extension for Arduino Remote Code Execution Vulnerability | Critical | 9.8 |
Visual Studio Code | - | - | - |
Threat Categories 8
| Threat Category | CVEs | Critical |
|---|---|---|
| Remote Code Execution | 42 | 3 |
| Elevation of Privilege | 28 | - |
| Denial of Service | 26 | - |
| Security Feature Bypass | 7 | - |
| Spoofing | 7 | - |
| Information Disclosure | 6 | - |
| Tampering | 1 | - |
| Unknown | 1 | - |
Affected Products 65
| Product | CVEs | Exploited |
|---|---|---|
| Windows Mobile Broadband | 15 | - |
| Windows Routing and Remote Access Service (RRAS) | 12 | - |
| Windows Kernel | 6 | - |
| Microsoft Graphics Component | 4 | - |
| Role: Windows Hyper-V | 4 | - |
| Microsoft Office | 3 | - |
| OpenSSH for Windows | 3 | - |
| Windows EFI Partition | 3 | - |
| .NET and Visual Studio | 2 | - |
| .NET, .NET Framework, Visual Studio | 2 | - |
| BranchCache | 2 | - |
| Microsoft Simple Certificate Enrollment Protocol | 2 | - |
| Power BI | 2 | - |
| Remote Desktop Client | 2 | - |
| Visual Studio Code | 2 | - |
| Windows Kerberos | 2 | - |
| Windows Kernel-Mode Drivers | 2 | - |
| Windows Network Address Translation (NAT) | 2 | - |
| Windows Secure Kernel Mode | 2 | - |
| Azure CLI | 1 | - |
| Azure Monitor | 1 | - |
| Azure Stack | 1 | - |
| Code Integrity Guard | 1 | - |
| Copilot Studio | 1 | - |
| DeepSpeed | 1 | - |
| Internet Small Computer Systems Interface (iSCSI) | 1 | - |
| Microsoft ActiveX | 1 | - |
| Microsoft Configuration Manager | 1 | - |
| Microsoft Defender for Endpoint | 1 | - |
| Microsoft Management Console | 1 | 1 |
| Microsoft Office Excel | 1 | - |
| Microsoft Office SharePoint | 1 | - |
| Microsoft Office Visio | 1 | - |
| Microsoft WDAC OLE DB provider for SQL | 1 | - |
| Microsoft Windows Speech | 1 | - |
| Outlook for Android | 1 | - |
| RPC Endpoint Mapper Service | 1 | - |
| Service Fabric | 1 | - |
| Sudo for Windows | 1 | - |
| Visual C++ Redistributable Installer | 1 | - |
| Visual Studio | 1 | - |
| Windows Ancillary Function Driver for WinSock | 1 | - |
| Windows BitLocker | 1 | - |
| Windows Common Log File System Driver | 1 | - |
| Windows Cryptographic Services | 1 | - |
| Windows Hyper-V | 1 | - |
| Windows Local Security Authority (LSA) | 1 | - |
| Windows MSHTML Platform | 1 | 1 |
| Windows NT OS Kernel | 1 | - |
| Windows NTFS | 1 | - |
| Windows Netlogon | 1 | - |
| Windows Online Certificate Status Protocol (OCSP) | 1 | - |
| Windows Print Spooler Components | 1 | - |
| Windows Remote Desktop | 1 | - |
| Windows Remote Desktop Licensing Service | 1 | - |
| Windows Remote Desktop Services | 1 | - |
| Windows Resilient File System (ReFS) | 1 | - |
| Windows Scripting | 1 | - |
| Windows Secure Channel | 1 | - |
| Windows Shell | 1 | - |
| Windows Standards-Based Storage Management Service | 1 | - |
| Windows Storage | 1 | - |
| Windows Storage Port Driver | 1 | - |
| Windows Telephony Server | 1 | - |
| Winlogon | 1 | - |