Microsoft October 2024 Security Updates

Discussion in 'Software' started by NICK ADSL UK, Oct 8, 2024.

Thread Status:
Not open for further replies.
  1. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    October 2024 Security Updates
    This release consists of the following 117 Microsoft CVEs:

    Tag CVE Base Score CVSS Vector Exploitability FAQs? Workarounds? Mitigations?
    Role: Windows Hyper-V CVE-2024-20659
    Windows Hyper-V CVE-2024-30092
    Windows EFI Partition CVE-2024-37976
    Windows Kernel CVE-2024-37979
    Windows EFI Partition CVE-2024-37982
    Windows EFI Partition CVE-2024-37983
    OpenSSH for Windows CVE-2024-38029
    Azure Monitor CVE-2024-38097
    Windows Netlogon CVE-2024-38124
    Windows Kerberos CVE-2024-38129
    BranchCache CVE-2024-38149
    Azure Stack CVE-2024-38179
    Windows Routing and Remote Access Service (RRAS) CVE-2024-38212
    .NET and Visual Studio CVE-2024-38229
    Windows Routing and Remote Access Service (RRAS) CVE-2024-38261 7
    Windows Remote Desktop Licensing Service CVE-2024-38262 7
    Windows Routing and Remote Access Service (RRAS) CVE-2024-38265
    Windows Routing and Remote Access Service (RRAS) CVE-2024-43453
    Windows Remote Desktop Services CVE-2024-43456
    Microsoft Configuration Manager CVE-2024-43468
    Service Fabric CVE-2024-43480
    Power BI CVE-2024-43481
    .NET, .NET Framework, Visual Studio CVE-2024-43483
    .NET, .NET Framework, Visual Studio CVE-2024-43484
    .NET and Visual Studio CVE-2024-43485
    Visual Studio Code CVE-2024-43488
    DeepSpeed CVE-2024-43497
    Windows Resilient File System (ReFS) CVE-2024-43500
    Windows Common Log File System Driver CVE-2024-43501
    Windows Kernel CVE-2024-43502
    Microsoft Office SharePoint CVE-2024-43503
    Microsoft Office Excel CVE-2024-43504 7
    Microsoft Office Visio CVE-2024-43505
    BranchCache CVE-2024-43506
    Microsoft Graphics Component CVE-2024-43508
    Microsoft Graphics Component CVE-2024-43509
    Windows Kernel CVE-2024-43511
    Windows Standards-Based Storage Management Service CVE-2024-43512
    Windows BitLocker CVE-2024-43513
    Windows NTFS CVE-2024-43514
    Internet Small Computer Systems Interface (iSCSI) CVE-2024-43515
    Windows Secure Kernel Mode CVE-2024-43516
    Microsoft ActiveX CVE-2024-43517
    Windows Telephony Server CVE-2024-43518
    Microsoft WDAC OLE DB provider for SQL CVE-2024-43519
    Windows Kernel CVE-2024-43520 5
    Role: Windows Hyper-V CVE-2024-43521
    Windows Local Security Authority (LSA) CVE-2024-43522 7
    Windows Mobile Broadband CVE-2024-43523
    Windows Mobile Broadband CVE-2024-43524
    Windows Mobile Broadband CVE-2024-43525
    Windows Mobile Broadband CVE-2024-43526
    Windows Kernel CVE-2024-43527
    Windows Secure Kernel Mode CVE-2024-43528
    Windows Print Spooler Components CVE-2024-43529
    RPC Endpoint Mapper Service CVE-2024-43532
    Remote Desktop Client CVE-2024-43533
    Microsoft Graphics Component CVE-2024-43534
    Windows Kernel-Mode Drivers CVE-2024-43535
    Windows Mobile Broadband CVE-2024-43536
    Windows Mobile Broadband CVE-2024-43537
    Windows Mobile Broadband CVE-2024-43538
    Windows Mobile Broadband CVE-2024-43540
    Microsoft Simple Certificate Enrollment Protocol CVE-2024-43541
    Windows Mobile Broadband CVE-2024-43542
    Windows Mobile Broadband CVE-2024-43543
    Microsoft Simple Certificate Enrollment Protocol CVE-2024-43544
    Windows Online Certificate Status Protocol (OCSP) CVE-2024-43545
    Windows Cryptographic Services CVE-2024-43546
    Windows Kerberos CVE-2024-43547
    Windows Routing and Remote Access Service (RRAS) CVE-2024-43549
    Windows Secure Channel CVE-2024-43550
    Windows Storage CVE-2024-43551
    Windows Shell CVE-2024-43552
    Windows NT OS Kernel CVE-2024-43553
    Windows Kernel-Mode Drivers CVE-2024-43554
    Windows Mobile Broadband CVE-2024-43555
    Microsoft Graphics Component CVE-2024-43556
    Windows Mobile Broadband CVE-2024-43557
    Windows Mobile Broadband CVE-2024-43558
    Windows Mobile Broadband CVE-2024-43559
    Windows Storage Port Driver CVE-2024-43560
    Windows Mobile Broadband CVE-2024-43561
    Windows Network Address Translation (NAT) CVE-2024-43562
    Windows Ancillary Function Driver for WinSock CVE-2024-43563
    Windows Routing and Remote Access Service (RRAS) CVE-2024-43564
    Windows Network Address Translation (NAT) CVE-2024-43565
    Role: Windows Hyper-V CVE-2024-43567
    Windows Kernel CVE-2024-43570
    Sudo for Windows CVE-2024-43571
    Microsoft Management Console CVE-2024-43572
    Windows MSHTML Platform CVE-2024-43573
    Microsoft Windows Speech CVE-2024-43574
    Role: Windows Hyper-V CVE-2024-43575
    Microsoft Office CVE-2024-43576
    OpenSSH for Windows CVE-2024-43581
    Windows Remote Desktop CVE-2024-43582
    Winlogon CVE-2024-43583
    Windows Scripting CVE-2024-43584
    Code Integrity Guard CVE-2024-43585
    Windows Routing and Remote Access Service (RRAS) CVE-2024-43589
    Visual C++ Redistributable Installer CVE-2024-43590
    Azure CLI CVE-2024-43591
    Windows Routing and Remote Access Service (RRAS) CVE-2024-43592
    Windows Routing and Remote Access Service (RRAS) CVE-2024-43593
    Remote Desktop Client CVE-2024-43599
    Visual Studio Code CVE-2024-43601
    Visual Studio CVE-2024-43603
    Outlook for Android CVE-2024-43604
    Windows Routing and Remote Access Service (RRAS) CVE-2024-43607
    Windows Routing and Remote Access Service (RRAS) CVE-2024-43608
    Microsoft Office CVE-2024-43609
    Windows Routing and Remote Access Service (RRAS) CVE-2024-43611
    Power BI CVE-2024-43612
    Microsoft Defender for Endpoint CVE-2024-43614
    OpenSSH for Windows CVE-2024-43615
    Microsoft Office CVE-2024-43616

    We are republishing 4 non-Microsoft CVEs:
    CNA Tag CVE FAQs? Workarounds? Mitigations?
    Hackerone Windows cURL Implementation CVE-2024-6197
    Chrome Microsoft Edge (Chromium-based) CVE-2024-7025
    Chrome Microsoft Edge (Chromium-based) CVE-2024-9369
    Chrome Microsoft Edge (Chromium-based) CVE-2024-9370

    Security Update Guide Blog Posts
    Date Blog Post
    June 27, 2024 Toward greater transparency: Unveiling Cloud Service CVEs
    April 9, 2024 Toward greater transparency: Security Update Guide now shares CWEs for CVEs
    January 6, 2023 Publishing CBL-Mariner CVEs on the Security Update Guide CVRF API
    January 11, 2022 Coming Soon: New Security Update Guide Notification System
    February 9, 2021 Continuing to Listen: Good News about the Security Update Guide API
    January 13, 2021 Security Update Guide Supports CVEs Assigned by Industry Partners
    December 8, 2020 Security Update Guide: Let’s keep the conversation going
    November 9, 2020 Vulnerability Descriptions in the New Version of the Security Update Guide
    Relevant Resources

      • Windows 10 and Windows 11 updates are cumulative. The monthly security release includes all security fixes for vulnerabilities that affect Windows 10 and Windows 11, in addition to non-security updates. The updates are available via the Microsoft Update Catalog. For information on lifecycle and support dates for Windows 10 and Windows 11 operating systems, please see Windows Lifecycle Facts Sheet.
      • A list of the latest servicing stack updates for each operating system can be found in ADV990001. This list will be updated whenever a new servicing stack update is released. It is important to install the latest servicing stack update.
      • In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features.
      • Customers running Windows Server 2008 R2, or Windows Server 2008 need to purchase the Extended Security Update to continue receiving security updates. See 4522133 for more information.
    Known Issues
    You can see these in more detail from the Deployments tab by selecting Known Issues column in the Edit Columns panel.

    For more information about Windows Known Issues, please see Windows message center (links to currently-supported versions of Windows are in the left pane).

    KB Article Applies To
    5044273 Windows 10, version 21H2, Windows 10, version 22H2
    5044280 Windows 11, version 21H2
    5044281 Windows Server 2022
    5044284 Windows 11 version 24H2
    5044306 Windows Server 2008 (Security-only update)
    5044320 Windows Server 2008 (Monthly Rollup)
    5044342 Windows Server 2012 (Monthly Rollup)
    5044343 Windows Server 2012 R2 (Monthly Rollup)

    Released: Oct 8, 2024
    https://msrc.microsoft.com/update-guide/releaseNote/2024-Oct

     
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds