Fortra VM will include the Microsoft Patch Tuesday checks in the NIRV 4.48.0 and FVM Agent 2.10 releases.

  • Microsoft addressed 86 vulnerabilities in this release, including 7 rated as Critical and 28 Remote Code Execution vulnerabilities.
  • This release also includes fixes for six vulnerabilities that have been exploited in the wild.
    • Microsoft Project Remote Code Execution Vulnerability (CVE-2024-38189)
      • This vulnerability requires an attacker to trick a victim into opening a malicious Microsoft Office Project file on a system with some Microsoft Office security settings disabled.
    • Windows Mark of the Web Security Feature Bypass Vulnerability (CVE-2024-38213)
    • Scripting Engine Memory Corruption Vulnerability (CVE-2024-38178)
    • CVE-2024-38107, CVE-2024-38106, and CVE-2024-38193 are Elevation of Privilege vulnerabilities that can be used to gain SYSTEM privileges on an affected system.
CVE/AdvisoryTitleTagMicrosoft Severity RatingBase ScoreMicrosoft ImpactExploitedPublicly Disclosed
CVE-2022-2601Redhat: CVE-2022-2601 grub2 – Buffer overflow in grub_font_construct_glyph() can lead to out-of-bound write and possible secure boot bypassWindows Secure BootImportant8.6Security Feature BypassNoNo
CVE-2024-38108Azure Stack Hub Spoofing VulnerabilityAzure StackImportant9.3SpoofingNoNo
CVE-2024-38123Windows Bluetooth Driver Information Disclosure VulnerabilityMicrosoft Bluetooth DriverImportant4.4Information DisclosureNoNo
CVE-2024-38159Windows Network Virtualization Remote Code Execution VulnerabilityWindows Network VirtualizationCritical9.1Remote Code ExecutionNoNo
CVE-2024-38160Windows Network Virtualization Remote Code Execution VulnerabilityWindows Network VirtualizationCritical9.1Remote Code ExecutionNoNo
CVE-2024-38161Windows Mobile Broadband Driver Remote Code Execution VulnerabilityWindows Mobile BroadbandImportant6.8Remote Code ExecutionNoNo
CVE-2024-38167.NET and Visual Studio Information Disclosure Vulnerability.NET and Visual StudioImportant6.5Information DisclosureNoNo
CVE-2024-38168.NET and Visual Studio Denial of Service Vulnerability.NET and Visual StudioImportant7.5Denial of ServiceNoNo
CVE-2024-38172Microsoft Excel Remote Code Execution VulnerabilityMicrosoft Office ExcelImportant7.8Remote Code ExecutionNoNo
CVE-2024-38178Scripting Engine Memory Corruption VulnerabilityWindows ScriptingImportant7.5Remote Code ExecutionYesNo
CVE-2024-38184Windows Kernel-Mode Driver Elevation of Privilege VulnerabilityWindows Kernel-Mode DriversImportant7.8Elevation of PrivilegeNoNo
CVE-2024-38191Kernel Streaming Service Driver Elevation of Privilege VulnerabilityWindows Kernel-Mode DriversImportant7.8Elevation of PrivilegeNoNo
CVE-2024-38193Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityWindows Ancillary Function Driver for WinSockImportant7.8Elevation of PrivilegeYesNo
CVE-2024-38196Windows Common Log File System Driver Elevation of Privilege VulnerabilityWindows Common Log File System DriverImportant7.8Elevation of PrivilegeNoNo
CVE-2024-38197Microsoft Teams for iOS Spoofing VulnerabilityMicrosoft TeamsImportant6.5SpoofingNoNo
CVE-2024-38198Windows Print Spooler Elevation of Privilege VulnerabilityWindows Print Spooler ComponentsImportant7.5Elevation of PrivilegeNoNo
CVE-2024-38199Windows Line Printer Daemon (LPD) Service Remote Code Execution VulnerabilityLine Printer Daemon Service (LPD)Important9.8Remote Code ExecutionNoYes
CVE-2024-38201Azure Stack Hub Elevation of Privilege VulnerabilityAzure StackImportant7Elevation of PrivilegeNoNo
CVE-2024-38213Windows Mark of the Web Security Feature Bypass VulnerabilityWindows Mark of the Web (MOTW)Moderate6.5Security Feature BypassYesNo
CVE-2023-40547Redhat: CVE-2023-40547 Shim – RCE in HTTP boot support may lead to secure boot bypassWindows Secure BootCritical8.3Security Feature BypassNoNo
CVE-2024-38084Microsoft OfficePlus Elevation of Privilege VulnerabilityMicrosoft OfficeImportant7.8Elevation of PrivilegeNoNo
CVE-2024-38063Windows TCP/IP Remote Code Execution VulnerabilityWindows TCP/IPCritical9.8Remote Code ExecutionNoNo
CVE-2024-38098Azure Connected Machine Agent Elevation of Privilege VulnerabilityAzure Connected Machine AgentImportant7.8Elevation of PrivilegeNoNo
CVE-2024-38106Windows Kernel Elevation of Privilege VulnerabilityWindows KernelImportant7Elevation of PrivilegeYesNo
CVE-2024-38107Windows Power Dependency Coordinator Elevation of Privilege VulnerabilityWindows Power Dependency CoordinatorImportant7.8Elevation of PrivilegeYesNo
CVE-2024-29995Windows Kerberos Elevation of Privilege VulnerabilityWindows KerberosImportant8.1Elevation of PrivilegeNoNo
CVE-2024-38114Windows IP Routing Management Snapin Remote Code Execution VulnerabilityWindows IP Routing Management SnapinImportant8.8Remote Code ExecutionNoNo
CVE-2024-38115Windows IP Routing Management Snapin Remote Code Execution VulnerabilityWindows IP Routing Management SnapinImportant8.8Remote Code ExecutionNoNo
CVE-2024-38116Windows IP Routing Management Snapin Remote Code Execution VulnerabilityWindows IP Routing Management SnapinImportant8.8Remote Code ExecutionNoNo
CVE-2024-38117NTFS Elevation of Privilege VulnerabilityWindows NTFSImportant7.8Elevation of PrivilegeNoNo
CVE-2024-38118Microsoft Local Security Authority (LSA) Server Information Disclosure VulnerabilityMicrosoft Local Security Authority Server (lsasrv)Important5.5Information DisclosureNoNo
CVE-2024-38121Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityWindows Routing and Remote Access Service (RRAS)Important8.8Remote Code ExecutionNoNo
CVE-2024-38122Microsoft Local Security Authority (LSA) Server Information Disclosure VulnerabilityMicrosoft Local Security Authority Server (lsasrv)Important5.5Information DisclosureNoNo
CVE-2024-38125Kernel Streaming WOW Thunk Service Driver Elevation of Privilege VulnerabilityMicrosoft Streaming ServiceImportant7.8Elevation of PrivilegeNoNo
CVE-2024-38126Windows Network Address Translation (NAT) Denial of Service VulnerabilityWindows Network Address Translation (NAT)Important7.5Denial of ServiceNoNo
CVE-2024-38127Windows Hyper-V Elevation of Privilege VulnerabilityWindows KernelImportant7.8Elevation of PrivilegeNoNo
CVE-2024-38128Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityWindows Routing and Remote Access Service (RRAS)Important8.8Remote Code ExecutionNoNo
CVE-2024-38130Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityWindows Routing and Remote Access Service (RRAS)Important8.8Remote Code ExecutionNoNo
CVE-2024-38131Clipboard Virtual Channel Extension Remote Code Execution VulnerabilityWindows Clipboard Virtual Channel ExtensionImportant8.8Remote Code ExecutionNoNo
CVE-2024-38132Windows Network Address Translation (NAT) Denial of Service VulnerabilityWindows Network Address Translation (NAT)Important7.5Denial of ServiceNoNo
CVE-2024-38133Windows Kernel Elevation of Privilege VulnerabilityWindows KernelImportant7.8Elevation of PrivilegeNoNo
CVE-2024-38134Kernel Streaming WOW Thunk Service Driver Elevation of Privilege VulnerabilityMicrosoft Streaming ServiceImportant7.8Elevation of PrivilegeNoNo
CVE-2024-38135Windows Resilient File System (ReFS) Elevation of Privilege VulnerabilityWindows NT OS KernelImportant7.8Elevation of PrivilegeNoNo
CVE-2024-38136Windows Resource Manager PSM Service Extension Elevation of Privilege VulnerabilityWindows Resource ManagerImportant7Elevation of PrivilegeNoNo
CVE-2024-38137Windows Resource Manager PSM Service Extension Elevation of Privilege VulnerabilityWindows Resource ManagerImportant7Elevation of PrivilegeNoNo
CVE-2024-38138Windows Deployment Services Remote Code Execution VulnerabilityWindows Deployment ServicesImportant7.5Remote Code ExecutionNoNo
CVE-2024-38140Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution VulnerabilityReliable Multicast Transport Driver (RMCAST)Critical9.8Remote Code ExecutionNoNo
CVE-2024-38141Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityWindows Ancillary Function Driver for WinSockImportant7.8Elevation of PrivilegeNoNo
CVE-2024-38142Windows Secure Kernel Mode Elevation of Privilege VulnerabilityWindows Secure Kernel ModeImportant7.8Elevation of PrivilegeNoNo
CVE-2024-38143Windows WLAN AutoConfig Service Elevation of Privilege VulnerabilityWindows WLAN Auto Config ServiceImportant4.2Elevation of PrivilegeNoNo
CVE-2024-38144Kernel Streaming WOW Thunk Service Driver Elevation of Privilege VulnerabilityMicrosoft Streaming ServiceImportant8.8Elevation of PrivilegeNoNo
CVE-2024-38145Windows Layer-2 Bridge Network Driver Denial of Service VulnerabilityWindows Layer-2 Bridge Network DriverImportant7.5Denial of ServiceNoNo
CVE-2024-38146Windows Layer-2 Bridge Network Driver Denial of Service VulnerabilityWindows Layer-2 Bridge Network DriverImportant7.5Denial of ServiceNoNo
CVE-2024-38147Microsoft DWM Core Library Elevation of Privilege VulnerabilityWindows DWM Core LibraryImportant7.8Elevation of PrivilegeNoNo
CVE-2024-38148Windows Secure Channel Denial of Service VulnerabilityWindows Transport Security Layer (TLS)Important7.5Denial of ServiceNoNo
CVE-2024-38150Windows DWM Core Library Elevation of Privilege VulnerabilityWindows DWM Core LibraryImportant7.8Elevation of PrivilegeNoNo
CVE-2024-38151Windows Kernel Information Disclosure VulnerabilityWindows KernelImportant5.5Information DisclosureNoNo
CVE-2024-38152Windows OLE Remote Code Execution VulnerabilityMicrosoft WDAC OLE DB provider for SQLImportant7.8Remote Code ExecutionNoNo
CVE-2024-38153Windows Kernel Elevation of Privilege VulnerabilityWindows KernelImportant7.8Elevation of PrivilegeNoNo
CVE-2024-38154Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityWindows Routing and Remote Access Service (RRAS)Important8.8Remote Code ExecutionNoNo
CVE-2024-38155Security Center Broker Information Disclosure VulnerabilityWindows Security CenterImportant5.5Information DisclosureNoNo
CVE-2024-38157Azure IoT SDK Remote Code Execution VulnerabilityAzure IoT SDKImportant7Remote Code ExecutionNoNo
CVE-2024-38158Azure IoT SDK Remote Code Execution VulnerabilityAzure IoT SDKImportant7Remote Code ExecutionNoNo
CVE-2024-38162Azure Connected Machine Agent Elevation of Privilege VulnerabilityAzure Connected Machine AgentImportant7.8Elevation of PrivilegeNoNo
CVE-2024-38165Windows Compressed Folder Tampering VulnerabilityWindows Compressed FolderImportant6.5TamperingNoNo
CVE-2024-38169Microsoft Office Visio Remote Code Execution VulnerabilityMicrosoft Office VisioImportant7.8Remote Code ExecutionNoNo
CVE-2024-38170Microsoft Excel Remote Code Execution VulnerabilityMicrosoft Office ExcelImportant7.1Remote Code ExecutionNoNo
CVE-2024-38171Microsoft PowerPoint Remote Code Execution VulnerabilityMicrosoft Office PowerPointImportant7.8Remote Code ExecutionNoNo
CVE-2024-38173Microsoft Outlook Remote Code Execution VulnerabilityMicrosoft Office OutlookImportant6.7Remote Code ExecutionNoNo
CVE-2024-38177Windows App Installer Spoofing VulnerabilityWindows App InstallerImportant7.8SpoofingNoNo
CVE-2024-38180Windows SmartScreen Security Feature Bypass VulnerabilityWindows SmartScreenImportant8.8Security Feature BypassNoNo
CVE-2024-38185Windows Kernel-Mode Driver Elevation of Privilege VulnerabilityWindows Kernel-Mode DriversImportant7.8Elevation of PrivilegeNoNo
CVE-2024-38186Windows Kernel-Mode Driver Elevation of Privilege VulnerabilityWindows Kernel-Mode DriversImportant7.8Elevation of PrivilegeNoNo
CVE-2024-38187Windows Kernel-Mode Driver Elevation of Privilege VulnerabilityWindows Kernel-Mode DriversImportant7.8Elevation of PrivilegeNoNo
CVE-2024-38189Microsoft Project Remote Code Execution VulnerabilityMicrosoft Office ProjectImportant8.8Remote Code ExecutionYesNo
CVE-2024-38195Azure CycleCloud Remote Code Execution VulnerabilityAzure CycleCloudImportant7.8Remote Code ExecutionNoNo
CVE-2024-38163Windows Update Stack Elevation of Privilege VulnerabilityWindows Update StackImportant7.8Elevation of PrivilegeNoNo
CVE-2022-3775Redhat: CVE-2022-3775 grub2 – Heap based out-of-bounds write when rendering certain Unicode sequencesWindows Secure BootCritical7.1Remote Code ExecutionNoNo
CVE-2024-38211Microsoft Dynamics 365 (on-premises) Cross-site Scripting VulnerabilityMicrosoft DynamicsImportant8.2SpoofingNoNo
CVE-2024-38120Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityWindows Routing and Remote Access Service (RRAS)Important8.8Remote Code ExecutionNoNo
CVE-2024-38214Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityWindows Routing and Remote Access Service (RRAS)Important6.5Information DisclosureNoNo
CVE-2024-38215Windows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityWindows Cloud Files Mini Filter DriverImportant7.8Elevation of PrivilegeNoNo
CVE-2024-38222Microsoft Edge (Chromium-based) Information Disclosure VulnerabilityMicrosoft Edge (Chromium-based) N/A NoNo
CVE-2024-38223Windows Initial Machine Configuration Elevation of Privilege VulnerabilityWindows Initial Machine ConfigurationImportant6.8Elevation of PrivilegeNoNo
CVE-2024-38109Azure Health Bot Elevation of Privilege VulnerabilityAzure Health BotCritical9.1Elevation of PrivilegeNoNo
CVE-2024-37968Windows DNS Spoofing VulnerabilityMicrosoft Windows DNSImportant7.5SpoofingNoNo

Quickly Find and Fix Your Most At-Risk Weaknesses

Watch this demo to see how Fortra VM can help.