Microsoft May 2024 Security Updates

Discussion in 'update alerts' started by NICK ADSL UK, May 14, 2024.

Thread Status:
Not open for further replies.
  1. NICK ADSL UK

    NICK ADSL UK Administrator

    Joined:
    May 13, 2003
    Posts:
    9,509
    Location:
    UK
    May 2024 Security Updates
    This release consists of the following 60 Microsoft CVEs:

    Tag
    CVE Base Score CVSS Vector Exploitability FAQs? Workarounds? Mitigations?
    Windows Task Scheduler CVE-2024-26238
    Microsoft Windows SCSI Class System File CVE-2024-29994
    Windows Common Log File System Driver CVE-2024-29996
    Windows Mobile Broadband CVE-2024-29997
    Windows Mobile Broadband CVE-2024-29998
    Windows Mobile Broadband CVE-2024-29999
    Windows Mobile Broadband CVE-2024-30000
    Windows Mobile Broadband CVE-2024-30001
    Windows Mobile Broadband CVE-2024-30002
    Windows Mobile Broadband CVE-2024-30003
    Windows Mobile Broadband CVE-2024-30004
    Windows Mobile Broadband CVE-2024-30005
    Microsoft WDAC OLE DB provider for SQL CVE-2024-30006
    Microsoft Brokering File System CVE-2024-30007
    Windows DWM Core Library CVE-2024-30008
    Windows Routing and Remote Access Service (RRAS) CVE-2024-30009
    Windows Hyper-V CVE-2024-30010
    Windows Hyper-V CVE-2024-30011
    Windows Mobile Broadband CVE-2024-30012
    Windows Routing and Remote Access Service (RRAS) CVE-2024-30014
    Windows Routing and Remote Access Service (RRAS) CVE-2024-30015
    Windows Cryptographic Services CVE-2024-30016
    Windows Hyper-V CVE-2024-30017
    Windows Kernel CVE-2024-30018
    Windows DHCP Server CVE-2024-30019
    Windows Cryptographic Services CVE-2024-30020
    Windows Mobile Broadband CVE-2024-30021
    Windows Routing and Remote Access Service (RRAS) CVE-2024-30022
    Windows Routing and Remote Access Service (RRAS) CVE-2024-30023
    Windows Routing and Remote Access Service (RRAS) CVE-2024-30024
    Windows Common Log File System Driver CVE-2024-30025
    Windows NTFS CVE-2024-30027
    Windows Win32K - ICOMP CVE-2024-30028
    Windows Routing and Remote Access Service (RRAS) CVE-2024-30029
    Windows Win32K - GRFX CVE-2024-30030
    Windows CNG Key Isolation Service CVE-2024-30031
    Windows DWM Core Library CVE-2024-30032
    Microsoft Windows Search Component CVE-2024-30033
    Windows Cloud Files Mini Filter Driver CVE-2024-30034
    Windows DWM Core Library CVE-2024-30035
    Windows Deployment Services CVE-2024-30036
    Windows Common Log File System Driver CVE-2024-30037
    Windows Win32K - ICOMP CVE-2024-30038
    Windows Remote Access Connection Manager CVE-2024-30039
    Windows MSHTML Platform CVE-2024-30040
    Microsoft Bing CVE-2024-30041
    Microsoft Office Excel CVE-2024-30042
    Microsoft Office SharePoint CVE-2024-30043
    Microsoft Office SharePoint CVE-2024-30044
    .NET and Visual Studio CVE-2024-30045
    Visual Studio CVE-2024-30046
    Microsoft Dynamics 365 Customer Insights CVE-2024-30047
    Microsoft Dynamics 365 Customer Insights CVE-2024-30048
    Windows Win32K - ICOMP CVE-2024-30049
    Windows Mark of the Web (MOTW) CVE-2024-30050
    Windows DWM Core Library CVE-2024-30051
    Azure Migrate CVE-2024-30053
    Power BI CVE-2024-30054 6.5
    Microsoft Edge (Chromium-based) CVE-2024-30055
    Microsoft Intune CVE-2024-30059

    We are republishing 7 non-Microsoft CVEs:
    CNA
    Tag CVE FAQs? Workarounds? Mitigations?
    Github Visual Studio CVE-2024-32002 Yes No No
    Github Visual Studio CVE-2024-32004 Yes No No
    Chrome Microsoft Edge (Chromium-based) CVE-2024-4331
    Chrome Microsoft Edge (Chromium-based) CVE-2024-4368
    Chrome Microsoft Edge (Chromium-based) CVE-2024-4558
    Chrome Microsoft Edge (Chromium-based) CVE-2024-4559
    Chrome Microsoft Edge (Chromium-based) CVE-2024-4671

    Security Update Guide Blog Posts
    Date
    Blog Post
    April 9, 2024 Toward greater transparency: Security Update Guide now shares CWEs for CVEs
    January 11, 2022 Coming Soon: New Security Update Guide Notification System
    February 9, 2021 Continuing to Listen: Good News about the Security Update Guide API
    January 13, 2021 Security Update Guide Supports CVEs Assigned by Industry Partners
    December 8, 2020 Security Update Guide: Let’s keep the conversation going
    November 9, 2020 Vulnerability Descriptions in the New Version of the Security Update Guide
    Relevant Resources
    • The new Hotpatching feature is now generally available. Please see Hotpatching feature for Windows Server Azure Edition virtual machines (VMs) for more information.
    • Windows 10 and Windows 11 updates are cumulative. The monthly security release includes all security fixes for vulnerabilities that affect Windows 10 and Windows 11, in addition to non-security updates. The updates are available via the Microsoft Update Catalog. For information on lifecycle and support dates for Windows 10 operating systems, please see Windows Lifecycle Facts Sheet.
    • Microsoft is improving Windows Release Notes. For more information, please see What's next for Windows release notes.
    • A list of the latest servicing stack updates for each operating system can be found in ADV990001. This list will be updated whenever a new servicing stack update is released. It is important to install the latest servicing stack update.
    • In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features.
    • Customers running Windows Server 2008 R2, or Windows Server 2008 need to purchase the Extended Security Update to continue receiving security updates. See 4522133 for more information.
    Known Issues
    You can see these in more detail from the Deployments tab by selecting Known Issues column in the Edit Columns panel.

    For more information about Windows Known Issues, please see Windows message center (links to currently-supported versions of Windows are in the left pane).

    KB Article Applies To
    5037768 Windows 10, version 21H2, Windows 10, version 22H2
    5037770 Windows 11, version 21H2
    5037771 Windows 11, version 22H2, Windows 11, version 23H2
    5037782 Windows Server 2022
    5037800 Windows Server 2008 (Monthly Rollup)
    5037836 Windows Server 2008 (Security-only update)
    Released: May 14, 2024
    May 2024 Security Updates - Release Notes - Security Update Guide - Microsoft
     
  2. NICK ADSL UK

    NICK ADSL UK Administrator

    Joined:
    May 13, 2003
    Posts:
    9,509
    Location:
    UK
    CVEs have been published or revised in the Security Update Guide
    May 15, 2024

    These common vulnerabilities and exposures (CVEs) were recently published or revised in the Microsoft Security Update Guide:

    CVE-2024-30009

    · Title: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

    · Version: 1.1

    · Reason for revision: Removed one of the FAQs. This is an information change only.

    · Originally released: May 14, 2024

    · Last updated: May 15, 2024

    · Aggregate CVE Severity Rating: Important

    CVE-2024-30041

    · Title: Microsoft Bing Search Spoofing Vulnerability

    · Version: 1.1

    · Reason for revision: Updated the build numbers. This is an informational update only.

    · Originally released: May 14, 2024

    · Last updated: May 15, 2024

    · Aggregate CVE Severity Rating: Important

    CVE-2024-30044

    · Title: Microsoft SharePoint Server Remote Code Execution Vulnerability

    · Version: 1.1

    · Reason for revision: Added an FAQ and updated the CVSS score. This is an informational change only.

    · Originally released: May 14, 2024

    · Last updated: May 15, 2024

    · Aggregate CVE Severity Rating: Critical

    CVE-2024-30046

    · Title: Visual Studio Denial of Service Vulnerability

    · Version: 2.0

    · Reason for revision: The following corrctions have been made: 1) Revised the Security Updates table to include .NET 7.0 and .NET 8.0 because these versions of .NET are affected by this vulnerability. Microsoft recommends that customers install the updates to be fully protected from the vulnerability. 2) Updated title to include .NET. This is an informational change only.

    · Originally released: May 14, 2024

    · Last updated: May 15, 2024

    · Aggregate CVE Severity Rating: Important

    CVE-2024-30053

    · Title: Azure Migrate Cross-Site Scripting Vulnerability

    · Version: 1.1

    · Reason for revision: Updated FAQ information. This is an informational change only.

    · Originally released: May 14, 2024

    · Last updated: May 15, 2024

    · Aggregate CVE Severity Rating: Important

    CVE-2024-30055

    · Title: Microsoft Edge (Chromium-based) Spoofing Vulnerability

    · Version: 1.1

    · Reason for revision: Updated CWE value. This is an informational change only.

    · Originally released: May 10, 2024

    · Last updated: May 15, 2024

    · Aggregate CVE Severity Rating: Low
     
  3. NICK ADSL UK

    NICK ADSL UK Administrator

    Joined:
    May 13, 2003
    Posts:
    9,509
    Location:
    UK
    CVEs have been published or revised in the Security Update Guide
    May 16, 2024

    These common vulnerabilities and exposures (CVEs) were recently published or revised in the Microsoft Security Update Guide:

    CVE-2024-30060

    · Title: Azure Monitor Agent Elevation of Privilege Vulnerability

    · Version: 1.0

    · Reason for revision: Information published.

    · Originally released: May 16, 2024

    · Last updated: May 16, 2024

    Aggregate CVE Severity Rating: Important
     
  4. NICK ADSL UK

    NICK ADSL UK Administrator

    Joined:
    May 13, 2003
    Posts:
    9,509
    Location:
    UK
    CVEs have been published or revised in the Security Update Guide
    May 25, 2024

    These common vulnerabilities and exposures (CVEs) were recently published or revised in the Microsoft Security Update Guide:

    CVE-2024-30056

    · Title: Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

    · Version: 1.0

    · Reason for revision: Information published.

    · Originally released: May 16, 2024

    · Last updated: May 16, 2024

    · Aggregate CVE Severity Rating: Important

    CVE-2024-4947

    · Title: Chromium: CVE-2024-4947 Type Confusion in V8

    · Version: 1.0

    · Reason for revision: Information published.

    · Originally released: May 16, 2024

    · Last updated: May 16, 2024

    · Aggregate CVE Severity Rating:

    CVE-2024-4948

    · Title: Chromium: CVE-2024-4948 Use after free in Dawn

    · Version: 1.0

    · Reason for revision: Information published.

    · Originally released: May 16, 2024

    · Last updated: May 16, 2024

    · Aggregate CVE Severity Rating:

    CVE-2024-4949

    Title: Chromium: CVE-2024-4949 Use
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.