FVM will include the Microsoft Patch Tuesday checks in the NIRV 4.56.0 and FVM Agent 2.17.

  • Microsoft addressed 70 vulnerabilities this release, including 16 rated as Critical.
  • CVE-2024-49138 – Microsoft has disclosed an actively exploited vulnerability that allows attackers to gain SYSTEM privileges on Windows devices. No further information is provided from Microsoft on how the security vulnerability was exploited in attacks at this moment.
CVE/AdvisoryTitleTagMicrosoft Severity RatingBase ScoreMicrosoft ImpactExploitedPublicly Disclosed
CVE-2024-43594System Center Operations Manager Elevation of Privilege VulnerabilitySystem Center Operations ManagerImportant7.3Elevation of PrivilegeNoNo
CVE-2024-49057Microsoft Defender for Endpoint on Android Spoofing VulnerabilityMicrosoft Defender for EndpointImportant8.1SpoofingNoNo
CVE-2024-49059Microsoft Office Elevation of Privilege VulnerabilityMicrosoft OfficeImportant7Elevation of PrivilegeNoNo
CVE-2024-49064Microsoft SharePoint Information Disclosure VulnerabilityMicrosoft Office SharePointImportant6.5Information DisclosureNoNo
CVE-2024-49068Microsoft SharePoint Elevation of Privilege VulnerabilityMicrosoft Office SharePointImportant8.2Elevation of PrivilegeNoNo
CVE-2024-49069Microsoft Excel Remote Code Execution VulnerabilityMicrosoft Office ExcelImportant7.8Remote Code ExecutionNoNo
CVE-2024-49070Microsoft SharePoint Remote Code Execution VulnerabilityMicrosoft Office SharePointImportant7.4Remote Code ExecutionNoNo
CVE-2024-49073Windows Mobile Broadband Driver Elevation of Privilege VulnerabilityWindows Mobile BroadbandImportant6.8Elevation of PrivilegeNoNo
CVE-2024-49074Windows Kernel-Mode Driver Elevation of Privilege VulnerabilityWindows Kernel-Mode DriversImportant7.8Elevation of PrivilegeNoNo
CVE-2024-49084Windows Kernel Elevation of Privilege VulnerabilityWindows KernelImportant7Elevation of PrivilegeNoNo
CVE-2024-49085Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityWindows Routing and Remote Access Service (RRAS)Important8.8Remote Code ExecutionNoNo
CVE-2024-49086Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityWindows Routing and Remote Access Service (RRAS)Important8.8Remote Code ExecutionNoNo
CVE-2024-49087Windows Mobile Broadband Driver Information Disclosure VulnerabilityWindows Mobile BroadbandImportant4.6Information DisclosureNoNo
CVE-2024-49089Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityWindows Routing and Remote Access Service (RRAS)Important7.2Remote Code ExecutionNoNo
CVE-2024-49091Windows  Domain Name Service Remote Code Execution VulnerabilityRole: DNS ServerImportant7.2Remote Code ExecutionNoNo
CVE-2024-49092Windows Mobile Broadband Driver Elevation of Privilege VulnerabilityWindows Mobile BroadbandImportant6.8Elevation of PrivilegeNoNo
CVE-2024-49093Windows Resilient File System (ReFS) Elevation of Privilege VulnerabilityWindows Resilient File System (ReFS)Important8.8Elevation of PrivilegeNoNo
CVE-2024-49094Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege VulnerabilityWindows Wireless Wide Area Network ServiceImportant6.6Elevation of PrivilegeNoNo
CVE-2024-49096Microsoft Message Queuing (MSMQ) Denial of Service VulnerabilityWindows Message QueuingImportant7.5Denial of ServiceNoNo
CVE-2024-49097Windows PrintWorkflowUserSvc Elevation of Privilege VulnerabilityWindows PrintWorkflowUserSvcImportant7Elevation of PrivilegeNoNo
CVE-2024-49098Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure VulnerabilityWindows Wireless Wide Area Network ServiceImportant4.3Information DisclosureNoNo
CVE-2024-49099Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure VulnerabilityWindows Wireless Wide Area Network ServiceImportant4.3Information DisclosureNoNo
CVE-2024-49101Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege VulnerabilityWindows Wireless Wide Area Network ServiceImportant6.6Elevation of PrivilegeNoNo
CVE-2024-49102Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityWindows Routing and Remote Access Service (RRAS)Important8.8Remote Code ExecutionNoNo
CVE-2024-49103Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure VulnerabilityWindows Wireless Wide Area Network ServiceImportant4.3Information DisclosureNoNo
CVE-2024-49104Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityWindows Routing and Remote Access Service (RRAS)Important8.8Remote Code ExecutionNoNo
CVE-2024-49106Windows Remote Desktop Services Remote Code Execution VulnerabilityWindows Remote Desktop ServicesCritical8.1Remote Code ExecutionNoNo
CVE-2024-49107WmsRepair Service Elevation of Privilege VulnerabilityWmsRepair ServiceImportant7.3Elevation of PrivilegeNoNo
CVE-2024-49108Windows Remote Desktop Services Remote Code Execution VulnerabilityWindows Remote Desktop ServicesCritical8.1Remote Code ExecutionNoNo
CVE-2024-49111Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege VulnerabilityWindows Wireless Wide Area Network ServiceImportant6.6Elevation of PrivilegeNoNo
CVE-2024-49115Windows Remote Desktop Services Remote Code Execution VulnerabilityWindows Remote Desktop ServicesCritical8.1Remote Code ExecutionNoNo
CVE-2024-49117Windows Hyper-V Remote Code Execution VulnerabilityRole: Windows Hyper-VCritical8.8Remote Code ExecutionNoNo
CVE-2024-49119Windows Remote Desktop Services Remote Code Execution VulnerabilityWindows Remote Desktop ServicesCritical8.1Remote Code ExecutionNoNo
CVE-2024-49120Windows Remote Desktop Services Remote Code Execution VulnerabilityWindows Remote Desktop ServicesCritical8.1Remote Code ExecutionNoNo
CVE-2024-49121Windows Lightweight Directory Access Protocol (LDAP) Denial of Service VulnerabilityWindows LDAP – Lightweight Directory Access ProtocolImportant7.5Denial of ServiceNoNo
CVE-2024-49122Microsoft Message Queuing (MSMQ) Remote Code Execution VulnerabilityWindows Message QueuingCritical8.1Remote Code ExecutionNoNo
CVE-2024-49123Windows Remote Desktop Services Remote Code Execution VulnerabilityWindows Remote Desktop ServicesCritical8.1Remote Code ExecutionNoNo
CVE-2024-49124Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution VulnerabilityWindows LDAP – Lightweight Directory Access ProtocolCritical8.1Remote Code ExecutionNoNo
CVE-2024-49125Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityWindows Routing and Remote Access Service (RRAS)Important8.8Remote Code ExecutionNoNo
CVE-2024-49126Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution VulnerabilityWindows Local Security Authority Subsystem Service (LSASS)Critical8.1Remote Code ExecutionNoNo
CVE-2024-49129Windows Remote Desktop Gateway (RD Gateway) Denial of Service VulnerabilityWindows Remote Desktop ServicesImportant7.5Denial of ServiceNoNo
CVE-2024-49132Windows Remote Desktop Services Remote Code Execution VulnerabilityWindows Remote DesktopCritical8.1Remote Code ExecutionNoNo
CVE-2024-49142Microsoft Access Remote Code Execution VulnerabilityMicrosoft Office AccessImportant7.8Remote Code ExecutionNoNo
CVE-2024-43600Microsoft Office Elevation of Privilege VulnerabilityMicrosoft OfficeImportant7.8Elevation of PrivilegeNoNo
CVE-2024-49062Microsoft SharePoint Information Disclosure VulnerabilityMicrosoft Office SharePointImportant6.5Information DisclosureNoNo
CVE-2024-49063Microsoft/Muzic Remote Code Execution VulnerabilityGitHubImportant8.4Remote Code ExecutionNoNo
CVE-2024-49065Microsoft Office Remote Code Execution VulnerabilityMicrosoft Office WordImportant5.5Remote Code ExecutionNoNo
CVE-2024-49072Windows Task Scheduler Elevation of Privilege VulnerabilityWindows Task SchedulerImportant7.8Elevation of PrivilegeNoNo
CVE-2024-49075Windows Remote Desktop Services Denial of Service VulnerabilityWindows Remote Desktop ServicesImportant7.5Denial of ServiceNoNo
CVE-2024-49076Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege VulnerabilityWindows Virtualization-Based Security (VBS) EnclaveImportant7.8Elevation of PrivilegeNoNo
CVE-2024-49077Windows Mobile Broadband Driver Elevation of Privilege VulnerabilityWindows Mobile BroadbandImportant6.8Elevation of PrivilegeNoNo
CVE-2024-49078Windows Mobile Broadband Driver Elevation of Privilege VulnerabilityWindows Mobile BroadbandImportant6.8Elevation of PrivilegeNoNo
CVE-2024-49079Input Method Editor (IME) Remote Code Execution VulnerabilityMicrosoft Office PublisherImportant7.8Remote Code ExecutionNoNo
CVE-2024-49080Windows IP Routing Management Snapin Remote Code Execution VulnerabilityWindows IP Routing Management SnapinImportant8.8Remote Code ExecutionNoNo
CVE-2024-49081Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege VulnerabilityWindows Wireless Wide Area Network ServiceImportant6.6Elevation of PrivilegeNoNo
CVE-2024-49082Windows File Explorer Information Disclosure VulnerabilityWindows File ExplorerImportant6.8Information DisclosureNoNo
CVE-2024-49083Windows Mobile Broadband Driver Elevation of Privilege VulnerabilityWindows Mobile BroadbandImportant6.8Elevation of PrivilegeNoNo
CVE-2024-49088Windows Common Log File System Driver Elevation of Privilege VulnerabilityWindows Common Log File System DriverImportant7.8Elevation of PrivilegeNoNo
CVE-2024-49090Windows Common Log File System Driver Elevation of Privilege VulnerabilityWindows Common Log File System DriverImportant7.8Elevation of PrivilegeNoNo
CVE-2024-49095Windows PrintWorkflowUserSvc Elevation of Privilege VulnerabilityWindows PrintWorkflowUserSvcImportant7Elevation of PrivilegeNoNo
CVE-2024-49109Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege VulnerabilityWindows Wireless Wide Area Network ServiceImportant6.6Elevation of PrivilegeNoNo
CVE-2024-49110Windows Mobile Broadband Driver Elevation of Privilege VulnerabilityWindows Mobile BroadbandImportant6.8Elevation of PrivilegeNoNo
CVE-2024-49112Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution VulnerabilityWindows LDAP – Lightweight Directory Access ProtocolCritical9.8Remote Code ExecutionNoNo
CVE-2024-49113Windows Lightweight Directory Access Protocol (LDAP) Denial of Service VulnerabilityWindows LDAP – Lightweight Directory Access ProtocolImportant7.5Denial of ServiceNoNo
CVE-2024-49114Windows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityWindows Cloud Files Mini Filter DriverImportant7.8Elevation of PrivilegeNoNo
CVE-2024-49116Windows Remote Desktop Services Remote Code Execution VulnerabilityWindows Remote Desktop ServicesCritical8.1Remote Code ExecutionNoNo
CVE-2024-49118Microsoft Message Queuing (MSMQ) Remote Code Execution VulnerabilityWindows Message QueuingCritical8.1Remote Code ExecutionNoNo
CVE-2024-49127Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution VulnerabilityWindows LDAP – Lightweight Directory Access ProtocolCritical8.1Remote Code ExecutionNoNo
CVE-2024-49128Windows Remote Desktop Services Remote Code Execution VulnerabilityWindows Remote Desktop ServicesCritical8.1Remote Code ExecutionNoNo
CVE-2024-49138Windows Common Log File System Driver Elevation of Privilege VulnerabilityWindows Common Log File System DriverImportant7.8Elevation of PrivilegeYesYes

Quickly Find and Fix Your Most At-Risk Weaknesses

Watch this demo to see how Fortra VM can help.