Jetzt Ausprobieren
Patch Tuesday

Microsoft Patch Tuesday – July 2024

9 min. read
09/07/2024
By Esben Dochy
Microsoft Patch Tuesday

⚡ TL;DR | Go Straight to the July 202Patch Tuesday Audit Report

Patch Tuesday is once again upon us. As always, our team has put together the monthly Patch Tuesday Report to help you manage your update progress. The audit report gives you a quick and clear overview of your Windows machines and their patching status. The July 2024 edition of Patch Tuesday brings us 142 new fixes, with 5 rated as critical and 2 exploited. We’ve listed the most important changes below.

Windows Hyper-V Elevation of Privilege Vulnerability

The first exploited vulnerability is one in Hyper-V, CVE-2024-38080 has a CVSS base score of 7.8. If exploited successfully, an attacker can gain SYSTEM privileges.

As per usual, Microsoft doesn’t give too much information about these exploits as they want people to be protected. But the vulnerability does seem limited to Windows 11 and Server 2022

Windows MSHTML Platform Spoofing Vulnerability

The second exploited vulnerability is more broad, affecting most, if not all supported Windows versions. CVE-2024-38112 has a CVSS base score of 7.5 however, exploitation requires an attacker to send the victim a malicious file that the victim would have to execute.

SharePoint & Windows Imaging Component RCE

Both SharePoint and the Windows Imaging Component have an RCE vulnerability that is rated as critical and also listed as more likely, to be exploited.

CVE-2024-38023 is the SharePoint RCE, which has a CVSS base score of 7.2. Microsoft lists the following regarding potential exploitation.

An authenticated attacker with Site Owner permissions or higher could upload a specially crafted file to the targeted SharePoint Server and craft specialized API requests to trigger deserialization of file’s parameters. This would enable the attacker to perform remote code execution in the context of the SharePoint Server.

CVE-2024-38060 is the WIC RCE and has a CVSS base score of 8.8. Exploitation requires an authenticated attacker to upload a malicious TIFF file to a server. Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.

Run the Patch Tuesday July 2024 Audit

To help manage your update progress, we’ve created the Patch Tuesday Audit that checks if the assets in your network are on the latest patch updates. The report has been color-coded to see which machines are up-to-date and which ones still need to be updated. As always, system administrators are urged to update their environment as soon as possible to ensure all endpoints are secured.

The Lansweeper Patch Tuesday report is automatically added to your Lansweeper Site. Lansweeper Sites is included in all our licenses without any additional cost and allows you to federate all your installations into one single view so all you need to do is look at one report, automatically added every patch Tuesday!

Patch Tuesday July 2024 CVE Codes & Titles

CVE NumberCVE Title
CVE-2024-38080Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2024-38112Windows MSHTML Platform Spoofing Vulnerability
CVE-2024-30061Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
CVE-2024-21417Windows Text Services Framework Elevation of Privilege Vulnerability
CVE-2024-28899Secure Boot Security Feature Bypass Vulnerability
CVE-2024-30081Windows NTLM Spoofing Vulnerability
CVE-2024-30098Windows Cryptographic Services Security Feature Bypass Vulnerability
CVE-2024-35264.NET and Visual Studio Remote Code Execution Vulnerability
CVE-2024-35270Windows iSCSI Service Denial of Service Vulnerability
CVE-2024-38088SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-38087SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-21332SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-21333SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-21335SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-21373SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-21398SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-21414SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-21415SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-21428SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-37318SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-37332SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-37331SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-37969Secure Boot Security Feature Bypass Vulnerability
CVE-2024-37970Secure Boot Security Feature Bypass Vulnerability
CVE-2024-37974Secure Boot Security Feature Bypass Vulnerability
CVE-2024-37981Secure Boot Security Feature Bypass Vulnerability
CVE-2024-37985Arm: CVE-2024-37985 Systematic Identification and Characterization of Proprietary Prefetchers
CVE-2024-37986Secure Boot Security Feature Bypass Vulnerability
CVE-2024-37987Secure Boot Security Feature Bypass Vulnerability
CVE-2024-38013Microsoft Windows Server Backup Elevation of Privilege Vulnerability
CVE-2024-38015Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability
CVE-2024-38022Windows Image Acquisition Elevation of Privilege Vulnerability
CVE-2024-38025Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
CVE-2024-38034Windows Filtering Platform Elevation of Privilege Vulnerability
CVE-2024-38041Windows Kernel Information Disclosure Vulnerability
CVE-2024-38043PowerShell Elevation of Privilege Vulnerability
CVE-2024-38517Github: CVE-2024-38517 TenCent RapidJSON Elevation of Privilege Vulnerability
CVE-2024-38051Windows Graphics Component Remote Code Execution Vulnerability
CVE-2024-38055Microsoft Windows Codecs Library Information Disclosure Vulnerability
CVE-2024-38056Microsoft Windows Codecs Library Information Disclosure Vulnerability
CVE-2024-38061DCOM Remote Cross-Session Activation Elevation of Privilege Vulnerability
CVE-2024-38062Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
CVE-2024-38064Windows TCP/IP Information Disclosure Vulnerability
CVE-2024-38071Windows Remote Desktop Licensing Service Denial of Service Vulnerability
CVE-2024-38072Windows Remote Desktop Licensing Service Denial of Service Vulnerability
CVE-2024-38077Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
CVE-2024-38086Azure Kinect SDK Remote Code Execution Vulnerability
CVE-2024-38091Microsoft WS-Discovery Denial of Service Vulnerability
CVE-2024-38102Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability
CVE-2024-38104Windows Fax Service Remote Code Execution Vulnerability
CVE-2024-26184Secure Boot Security Feature Bypass Vulnerability
CVE-2024-30013Windows MultiPoint Services Remote Code Execution Vulnerability
CVE-2024-32987Microsoft SharePoint Server Information Disclosure Vulnerability
CVE-2024-30071Windows Remote Access Connection Manager Information Disclosure Vulnerability
CVE-2024-30079Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
CVE-2024-3596CERT/CC: CVE-2024-3596 RADIUS Protocol Spoofing Vulnerability
CVE-2024-30105.NET Core and Visual Studio Denial of Service Vulnerability
CVE-2024-35261Azure Network Watcher VM Extension Elevation of Privilege Vulnerability
CVE-2024-35266Azure DevOps Server Spoofing Vulnerability
CVE-2024-35267Azure DevOps Server Spoofing Vulnerability
CVE-2024-35271SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-35272SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-20701SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-21303SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-21308SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-21317SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-21425SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-21331SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-37319SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-37320SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-37321SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-37322SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-37323SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-37324SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-21449SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-37326SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-37327SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-37328SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-37329SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-37330SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-37334Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-37333SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-37336SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-28928SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-35256SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-37971Secure Boot Security Feature Bypass Vulnerability
CVE-2024-37972Secure Boot Security Feature Bypass Vulnerability
CVE-2024-37973Secure Boot Security Feature Bypass Vulnerability
CVE-2024-37975Secure Boot Security Feature Bypass Vulnerability
CVE-2024-37977Secure Boot Security Feature Bypass Vulnerability
CVE-2024-37978Secure Boot Security Feature Bypass Vulnerability
CVE-2024-37984Secure Boot Security Feature Bypass Vulnerability
CVE-2024-37988Secure Boot Security Feature Bypass Vulnerability
CVE-2024-37989Secure Boot Security Feature Bypass Vulnerability
CVE-2024-38010Secure Boot Security Feature Bypass Vulnerability
CVE-2024-38011Secure Boot Security Feature Bypass Vulnerability
CVE-2024-38017Microsoft Message Queuing Information Disclosure Vulnerability
CVE-2024-38019Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
CVE-2024-38020Microsoft Outlook Spoofing Vulnerability
CVE-2024-38027Windows Line Printer Daemon Service Denial of Service Vulnerability
CVE-2024-38028Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
CVE-2024-38030Windows Themes Spoofing Vulnerability
CVE-2024-38031Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
CVE-2024-38032Microsoft Xbox Remote Code Execution Vulnerability
CVE-2024-38033PowerShell Elevation of Privilege Vulnerability
CVE-2024-38044DHCP Server Service Remote Code Execution Vulnerability
CVE-2024-38047PowerShell Elevation of Privilege Vulnerability
CVE-2024-38048Windows Network Driver Interface Specification (NDIS) Denial of Service Vulnerability
CVE-2024-38049Windows Distributed Transaction Coordinator Remote Code Execution Vulnerability
CVE-2024-38050Windows Workstation Service Elevation of Privilege Vulnerability
CVE-2024-38053Windows Layer-2 Bridge Network Driver Remote Code Execution Vulnerability
CVE-2024-38057Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
CVE-2024-38058BitLocker Security Feature Bypass Vulnerability
CVE-2024-38065Secure Boot Security Feature Bypass Vulnerability
CVE-2024-38067Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
CVE-2024-38068Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
CVE-2024-38069Windows Enroll Engine Security Feature Bypass Vulnerability
CVE-2024-38070Windows LockDown Policy (WLDP) Security Feature Bypass Vulnerability
CVE-2024-38073Windows Remote Desktop Licensing Service Denial of Service Vulnerability
CVE-2024-38074Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
CVE-2024-38076Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
CVE-2024-38078Xbox Wireless Adapter Remote Code Execution Vulnerability
CVE-2024-38081.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
CVE-2024-38089Microsoft Defender for IoT Elevation of Privilege Vulnerability
CVE-2024-38092Azure CycleCloud Elevation of Privilege Vulnerability
CVE-2024-38095.NET and Visual Studio Denial of Service Vulnerability
CVE-2024-38101Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability
CVE-2024-38105Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability
CVE-2024-38023Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2024-38024Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2024-38054Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
CVE-2024-38059Win32k Elevation of Privilege Vulnerability
CVE-2024-38060Windows Imaging Component Remote Code Execution Vulnerability
CVE-2024-38085Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2024-38100Windows File Explorer Elevation of Privilege Vulnerability
CVE-2024-38021Microsoft Office Remote Code Execution Vulnerability
CVE-2024-38052Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
CVE-2024-38066Windows Win32k Elevation of Privilege Vulnerability
CVE-2024-38079Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2024-38094Microsoft SharePoint Remote Code Execution Vulnerability
CVE-2024-38099Windows Remote Desktop Licensing Service Denial of Service Vulnerability
CVE-2024-39684Github: CVE-2024-39684 TenCent RapidJSON Elevation of Privilege Vulnerability