Patch Tuesday Archive
Patch Tuesday December 2024
Total CVEs
75
Critical
19
Important
54
Exploited
1
Publicly Disclosed
1
All CVEs this month 75
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2024-43594 | Microsoft System Center Elevation of Privilege Vulnerability | Important | 7.3 |
System Center | - | - | - |
| CVE-2024-49057 | Microsoft Defender for Endpoint on Android Spoofing Vulnerability | Important | 8.1 |
Microsoft Defender for Endpoint | - | - | - |
| CVE-2024-49059 | Microsoft Office Elevation of Privilege Vulnerability | Important | 7 |
Microsoft Office | - | - | - |
| CVE-2024-49064 | Microsoft SharePoint Information Disclosure Vulnerability | Important | 6.5 |
Microsoft Office SharePoint | - | - | - |
| CVE-2024-49068 | Microsoft SharePoint Elevation of Privilege Vulnerability | Important | 8.2 |
Microsoft Office SharePoint | - | - | - |
| CVE-2024-49069 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2024-49070 | Microsoft SharePoint Remote Code Execution Vulnerability | Important | 7.4 |
Microsoft Office SharePoint | - | - | - |
| CVE-2024-49073 | Windows Mobile Broadband Driver Elevation of Privilege Vulnerability | Important | 6.8 |
Windows Mobile Broadband | - | - | - |
| CVE-2024-49074 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel-Mode Drivers | - | - | - |
| CVE-2024-49084 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7 |
Windows Kernel | - | - | - |
| CVE-2024-49085 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Important | 8.8 |
Windows Routing and Remote Access Service (RRAS) | - | - | - |
| CVE-2024-49086 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Important | 8.8 |
Windows Routing and Remote Access Service (RRAS) | - | - | - |
| CVE-2024-49087 | Windows Mobile Broadband Driver Information Disclosure Vulnerability | Important | 4.6 |
Windows Mobile Broadband | - | - | - |
| CVE-2024-49089 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Important | 7.2 |
Windows Routing and Remote Access Service (RRAS) | - | - | - |
| CVE-2024-49091 | Windows Domain Name Service Remote Code Execution Vulnerability | Important | 7.2 |
Role: DNS Server | - | - | - |
| CVE-2024-49092 | Windows Mobile Broadband Driver Elevation of Privilege Vulnerability | Important | 6.8 |
Windows Mobile Broadband | - | - | - |
| CVE-2024-49093 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | Important | 8.8 |
Windows Resilient File System (ReFS) | - | - | - |
| CVE-2024-49094 | Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | Important | 6.6 |
Windows Wireless Wide Area Network Service | - | - | - |
| CVE-2024-49096 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | Important | 7.5 |
Windows Message Queuing | - | - | - |
| CVE-2024-49097 | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | Important | 7 |
Windows PrintWorkflowUserSvc | - | - | - |
| CVE-2024-49098 | Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability | Important | 4.3 |
Windows Wireless Wide Area Network Service | - | - | - |
| CVE-2024-49099 | Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability | Important | 4.3 |
Windows Wireless Wide Area Network Service | - | - | - |
| CVE-2024-49101 | Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | Important | 6.6 |
Windows Wireless Wide Area Network Service | - | - | - |
| CVE-2024-49102 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Important | 8.8 |
Windows Routing and Remote Access Service (RRAS) | - | - | - |
| CVE-2024-49103 | Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability | Important | 4.3 |
Windows Wireless Wide Area Network Service | - | - | - |
| CVE-2024-49104 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Important | 8.8 |
Windows Routing and Remote Access Service (RRAS) | - | - | - |
| CVE-2024-49105 | Remote Desktop Client Remote Code Execution Vulnerability | Critical | 8.4 |
Remote Desktop Client | - | - | - |
| CVE-2024-49106 | Windows Remote Desktop Services Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Remote Desktop Services | - | - | - |
| CVE-2024-49107 | WmsRepair Service Elevation of Privilege Vulnerability | Important | 7.3 |
WmsRepair Service | - | - | - |
| CVE-2024-49108 | Windows Remote Desktop Services Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Remote Desktop Services | - | - | - |
| CVE-2024-49111 | Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | Important | 6.6 |
Windows Wireless Wide Area Network Service | - | - | - |
| CVE-2024-49115 | Windows Remote Desktop Services Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Remote Desktop Services | - | - | - |
| CVE-2024-49117 | Windows Hyper-V Remote Code Execution Vulnerability | Critical | 8.8 |
Role: Windows Hyper-V | - | - | - |
| CVE-2024-49119 | Windows Remote Desktop Services Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Remote Desktop Services | - | - | - |
| CVE-2024-49121 | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | Important | 7.5 |
Windows LDAP - Lightweight Directory Access Protocol | - | - | - |
| CVE-2024-49122 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Message Queuing | - | - | - |
| CVE-2024-49123 | Windows Remote Desktop Services Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Remote Desktop Services | - | - | - |
| CVE-2024-49124 | Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability | Critical | 8.1 |
Windows LDAP - Lightweight Directory Access Protocol | - | - | - |
| CVE-2024-49125 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Important | 8.8 |
Windows Routing and Remote Access Service (RRAS) | - | - | - |
| CVE-2024-49126 | Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Local Security Authority Subsystem Service (LSASS) | - | - | - |
| CVE-2024-49129 | Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability | Important | 7.5 |
Windows Remote Desktop Services | - | - | - |
| CVE-2024-49132 | Windows Remote Desktop Services Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Remote Desktop | - | - | - |
| CVE-2024-49142 | Microsoft Access Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Access | - | - | - |
| ADV240002 | Microsoft Office Defense in Depth Update | Moderate | - | Microsoft Office | - | - | - |
| CVE-2024-49147 | Microsoft Update Catalog Elevation of Privilege Vulnerability | Critical | 9.8 |
Microsoft Update Catalog | - | - | - |
| CVE-2024-43600 | Microsoft Office Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2024-49062 | Microsoft SharePoint Information Disclosure Vulnerability | Important | 6.5 |
Microsoft Office SharePoint | - | - | - |
| CVE-2024-49063 | Microsoft/Muzic Remote Code Execution Vulnerability | Important | 8.4 |
GitHub | - | - | - |
| CVE-2024-49065 | Microsoft Office Remote Code Execution Vulnerability | Important | 5.5 |
Microsoft Office Word | - | - | - |
| CVE-2024-49072 | Windows Task Scheduler Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Task Scheduler | - | - | - |
| CVE-2024-49075 | Windows Remote Desktop Services Denial of Service Vulnerability | Important | 7.5 |
Windows Remote Desktop Services | - | - | - |
| CVE-2024-49076 | Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Virtualization-Based Security (VBS) Enclave | - | - | - |
| CVE-2024-49077 | Windows Mobile Broadband Driver Elevation of Privilege Vulnerability | Important | 6.8 |
Windows Mobile Broadband | - | - | - |
| CVE-2024-49078 | Windows Mobile Broadband Driver Elevation of Privilege Vulnerability | Important | 6.8 |
Windows Mobile Broadband | - | - | - |
| CVE-2024-49079 | Input Method Editor (IME) Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Publisher | - | - | - |
| CVE-2024-49080 | Windows IP Routing Management Snapin Remote Code Execution Vulnerability | Important | 8.8 |
Windows IP Routing Management Snapin | - | - | - |
| CVE-2024-49081 | Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | Important | 6.6 |
Windows Wireless Wide Area Network Service | - | - | - |
| CVE-2024-49082 | Windows File Explorer Information Disclosure Vulnerability | Important | 6.8 |
Windows File Explorer | - | - | - |
| CVE-2024-49083 | Windows Mobile Broadband Driver Elevation of Privilege Vulnerability | Important | 6.8 |
Windows Mobile Broadband | - | - | - |
| CVE-2024-49088 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Common Log File System Driver | - | - | - |
| CVE-2024-49090 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Common Log File System Driver | - | - | - |
| CVE-2024-49095 | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | Important | 7 |
Windows PrintWorkflowUserSvc | - | - | - |
| CVE-2024-49110 | Windows Mobile Broadband Driver Elevation of Privilege Vulnerability | Important | 6.8 |
Windows Mobile Broadband | - | - | - |
| CVE-2024-49112 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | Critical | 9.8 |
Windows LDAP - Lightweight Directory Access Protocol | - | - | - |
| CVE-2024-49113 | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | Important | 7.5 |
Windows LDAP - Lightweight Directory Access Protocol | - | - | - |
| CVE-2024-49114 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Cloud Files Mini Filter Driver | - | - | - |
| CVE-2024-49116 | Windows Remote Desktop Services Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Remote Desktop Services | - | - | - |
| CVE-2024-49118 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Message Queuing | - | - | - |
| CVE-2024-49127 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | Critical | 8.1 |
Windows LDAP - Lightweight Directory Access Protocol | - | - | - |
| CVE-2024-49128 | Windows Remote Desktop Services Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Remote Desktop Services | - | - | - |
| CVE-2024-49138 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Common Log File System Driver | Yes | Yes | - |
| CVE-2024-49041 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Moderate | 4.3 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2024-49071 | Windows Defender Information Disclosure Vulnerability | Critical | 6.5 |
Windows Defender | - | - | - |
| CVE-2024-49120 | Windows Remote Desktop Services Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Remote Desktop Services | - | - | - |
| CVE-2024-49109 | Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | Important | 6.6 |
Windows Wireless Wide Area Network Service | - | - | - |
Threat Categories 6
| Threat Category | CVEs | Critical |
|---|---|---|
| Remote Code Execution | 31 | 17 |
| Elevation of Privilege | 28 | 1 |
| Information Disclosure | 8 | 1 |
| Denial of Service | 5 | - |
| Spoofing | 2 | - |
| Defense in Depth | 1 | - |
Affected Products 34
| Product | CVEs | Exploited |
|---|---|---|
| Windows Remote Desktop Services | 10 | - |
| Windows Wireless Wide Area Network Service | 8 | - |
| Windows Mobile Broadband | 7 | - |
| Windows Routing and Remote Access Service (RRAS) | 6 | - |
| Windows LDAP - Lightweight Directory Access Protocol | 5 | - |
| Microsoft Office SharePoint | 4 | - |
| Microsoft Office | 3 | - |
| Windows Common Log File System Driver | 3 | 1 |
| Windows Message Queuing | 3 | - |
| Windows PrintWorkflowUserSvc | 2 | - |
| GitHub | 1 | - |
| Microsoft Defender for Endpoint | 1 | - |
| Microsoft Edge (Chromium-based) | 1 | - |
| Microsoft Office Access | 1 | - |
| Microsoft Office Excel | 1 | - |
| Microsoft Office Publisher | 1 | - |
| Microsoft Office Word | 1 | - |
| Microsoft Update Catalog | 1 | - |
| Remote Desktop Client | 1 | - |
| Role: DNS Server | 1 | - |
| Role: Windows Hyper-V | 1 | - |
| System Center | 1 | - |
| Windows Cloud Files Mini Filter Driver | 1 | - |
| Windows Defender | 1 | - |
| Windows File Explorer | 1 | - |
| Windows IP Routing Management Snapin | 1 | - |
| Windows Kernel | 1 | - |
| Windows Kernel-Mode Drivers | 1 | - |
| Windows Local Security Authority Subsystem Service (LSASS) | 1 | - |
| Windows Remote Desktop | 1 | - |
| Windows Resilient File System (ReFS) | 1 | - |
| Windows Task Scheduler | 1 | - |
| Windows Virtualization-Based Security (VBS) Enclave | 1 | - |
| WmsRepair Service | 1 | - |