PatchSiren

Microsoft CVE debriefs · Page 63

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited Microsoft CVE published 2024-12-10

CVE-2024-49138

CVE-2024-49138 is a Microsoft Windows vulnerability in the Common Log File System (CLFS) driver involving a heap-based buffer overflow. CISA added it to the Known Exploited Vulnerabilities catalog on 2024-12-10, which makes it a high-priority issue for defenders. The safest response is to follow Microsoft’s update guidance and remediate affected Windows systems as soon as possible.

Known exploited Microsoft CVE published 2024-11-12

CVE-2024-49039

CVE-2024-49039 is a Microsoft Windows privilege escalation vulnerability affecting Task Scheduler. CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on 2024-11-12 and marked it as having known ransomware campaign use. For defenders, that makes this a priority Windows issue to remediate using vendor guidance, with CISA’s due date set to 2024-12-03.

Known exploited Microsoft CVE published 2024-11-12

CVE-2024-43451

CVE-2024-43451 is a Microsoft Windows issue involving NTLMv2 hash disclosure and spoofing. CISA added it to the Known Exploited Vulnerabilities catalog on 2024-11-12, which is a strong signal to prioritize remediation quickly. The CISA entry sets a remediation due date of 2024-12-03 and points operators to vendor guidance for mitigation.

Known exploited Microsoft CVE published 2024-10-22

CVE-2024-38094

CVE-2024-38094 is a Microsoft SharePoint deserialization vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2024-10-22. CISA also marks this entry as having known ransomware campaign use, which makes it a high-priority issue for any organization running SharePoint. The supplied source corpus does not include version-specific impact or exploit mechanics, so the defensive takeaw [truncated]

Known exploited Microsoft CVE published 2024-10-15

CVE-2024-30088

CVE-2024-30088 is a Microsoft Windows Kernel time-of-check time-of-use (TOCTOU) race condition vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2024-10-15. The supplied corpus identifies it as known exploited and notes known ransomware campaign use. Because the provided sources are limited, this debrief does not add impact or affected-version details beyond the official records.

Known exploited Microsoft CVE published 2024-10-08

CVE-2024-43573

CVE-2024-43573 is a Microsoft Windows MSHTML platform spoofing vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. The KEV listing indicates the issue has been observed as exploited in the wild, so it should be treated as a high-priority remediation item. CISA’s required action is to apply vendor mitigations per Microsoft’s instructions, or discontinue use of the product if mitig [truncated]

Known exploited Microsoft CVE published 2024-10-08

CVE-2024-43572

CVE-2024-43572 is a Microsoft Windows Management Console remote code execution vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2024-10-08. Because it is on the KEV list, defenders should treat it as actively exploited and prioritize remediation using Microsoft’s guidance. CISA’s required action is to apply vendor mitigations or discontinue use if mitigations are unavailable.

Known exploited Microsoft CVE published 2024-09-18

CVE-2020-0618

CVE-2020-0618 is a Microsoft SQL Server Reporting Services remote code execution vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. Because it is in KEV, security teams should treat it as a high-priority remediation item and follow vendor mitigation guidance; CISA’s required action is to apply mitigations per vendor instructions or discontinue use if mitigations are unavailable.

Known exploited Microsoft CVE published 2024-09-16

CVE-2024-43461

CVE-2024-43461 is a Microsoft Windows MSHTML platform spoofing vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2024-09-16. Because it is on the KEV list, defenders should treat it as a high-priority remediation item and follow vendor mitigation guidance promptly.

HIGH Microsoft CVE published 2024-09-10

CVE-2024-43455

CVE-2024-43455 is a Microsoft Windows Remote Desktop Licensing Service spoofing vulnerability disclosed on 2024-09-10 and rated 8.8 (High). NVD lists affected Windows Server releases from 2008 SP2 through 2022 23H2, with fixed build thresholds for newer releases. Because the CVSS vector is network-reachable, requires only low privileges, and needs no user interaction, administrators should treat it as a h [truncated]

HIGH Microsoft CVE published 2024-09-10

CVE-2024-38250

CVE-2024-38250 is a Microsoft-reported elevation of privilege vulnerability with a CVSS 3.1 score of 7.8. The NVD record describes it as affecting the Windows Graphics Component and associates it with Microsoft updates released on 2024-09-10, with no KEV designation in the supplied data.

Known exploited Microsoft CVE published 2024-09-10

CVE-2024-38226

CVE-2024-38226 is a Microsoft Publisher vulnerability described by Microsoft as a protection mechanism failure and placed by CISA into its Known Exploited Vulnerabilities catalog on 2024-09-10. Because CISA lists it as known exploited, organizations using Publisher should treat it as urgent and follow Microsofts guidance or remove use of the product if mitigations are not available.

Known exploited Microsoft CVE published 2024-09-10

CVE-2024-38217

CVE-2024-38217 is a Microsoft Windows Mark of the Web (MOTW) protection mechanism failure vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2024-09-10, with remediation due by 2024-10-01, which means it should be treated as a high-priority defensive item. The supplied corpus does not include CVSS scoring or deeper technical detail, so organizations should rely on Microsoft’s g [truncated]

Known exploited Microsoft CVE published 2024-09-10

CVE-2024-38014

CVE-2024-38014 is a Microsoft Windows Installer improper privilege management issue that CISA added to its Known Exploited Vulnerabilities catalog on 2024-09-10. Because it is in KEV, defenders should treat it as an active-exposure priority and follow Microsoft guidance promptly. CISA’s listed remediation deadline is 2024-10-01. The supplied corpus does not provide CVSS scoring or additional technical det [truncated]

Known exploited Microsoft CVE published 2024-08-21

CVE-2021-31196

CVE-2021-31196 is a Microsoft Exchange Server information disclosure vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2024-08-21. That KEV listing means organizations should treat it as actively exploited and prioritize mitigation on any affected Exchange Server deployment. CISA’s required action is to apply vendor mitigations or discontinue use of the product if mitigations [truncated]

Known exploited Microsoft CVE published 2024-08-13

CVE-2024-38213

CVE-2024-38213 is a Microsoft Windows SmartScreen security feature bypass vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2024-08-13. Because it is on the KEV list, defenders should treat it as a priority remediation item and follow Microsoft’s vendor guidance.

Known exploited Microsoft CVE published 2024-08-13

CVE-2024-38193

CVE-2024-38193 is a Microsoft Windows privilege escalation vulnerability in the Ancillary Function Driver for WinSock. CISA added it to the Known Exploited Vulnerabilities catalog on 2024-08-13, which makes this a high-priority remediation item for Windows environments.

Known exploited Microsoft CVE published 2024-08-13

CVE-2024-38189

CVE-2024-38189 affects Microsoft Project and is listed by CISA in the Known Exploited Vulnerabilities catalog, which means it has been flagged by a trusted authority as actively exploited in the wild. The supplied corpus does not include full technical details or CVSS data, but the KEV listing alone makes this a high-priority issue for any environment that uses Microsoft Project. CISA’s required action is [truncated]

Known exploited Microsoft CVE published 2024-08-13

CVE-2024-38178

CVE-2024-38178 is a Microsoft Windows Scripting Engine memory corruption vulnerability that CISA marked as a known exploited issue on 2024-08-13. That KEV designation makes it a high-priority defensive item even though the supplied corpus does not include CVSS, affected-version details, or exploitation mechanics. Organizations should treat remediation as time-sensitive and follow Microsoft and CISA guidan [truncated]

Known exploited Microsoft CVE published 2024-08-13

CVE-2024-38107

CVE-2024-38107 is a Microsoft Windows privilege escalation vulnerability affecting Power Dependency Coordinator. CISA added it to the Known Exploited Vulnerabilities catalog on 2024-08-13, which makes it a priority for defenders to address using Microsoft’s guidance and timely patching.

Known exploited Microsoft CVE published 2024-08-13

CVE-2024-38106

CVE-2024-38106 is a Microsoft Windows Kernel Privilege Escalation vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2024-08-13. Because it is listed in KEV, defenders should treat it as actively exploited in the wild and prioritize remediation on affected Windows systems. The available public record in this corpus does not provide a CVSS score, so operational urgency should b [truncated]

Known exploited Microsoft CVE published 2024-08-05

CVE-2018-0824

CVE-2018-0824 is a Microsoft Windows COM for Windows deserialization-of-untrusted-data vulnerability that CISA listed in the Known Exploited Vulnerabilities catalog on 2024-08-05. Organizations should treat it as an urgent remediation item and follow Microsoft’s advisory guidance; CISA’s KEV entry says to apply vendor mitigations or discontinue use of the product if mitigations are unavailable.

Known exploited Microsoft CVE published 2024-07-23

CVE-2012-4792

CVE-2012-4792 is a Microsoft Internet Explorer use-after-free vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2024-07-23. CISA’s note says the impacted product is end-of-life and should be disconnected if still in use, so defenders should treat any remaining Internet Explorer exposure as a legacy-risk issue that needs removal or isolation rather than routine patching.

Known exploited Microsoft CVE published 2024-07-09

CVE-2024-38112

CVE-2024-38112 is a Microsoft Windows MSHTML platform spoofing vulnerability that CISA placed in its Known Exploited Vulnerabilities catalog on 2024-07-09. The KEV listing indicates known exploitation and sets a remediation due date of 2024-07-30. Use Microsoft’s vendor guidance and the official reference links for mitigation details.

Known exploited Microsoft CVE published 2024-07-09

CVE-2024-38080

CVE-2024-38080 is a Microsoft Windows Hyper-V privilege escalation vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2024-07-09. That designation means defenders should treat it as a priority exposure and review Microsoft guidance for affected Windows and Hyper-V deployments. The supplied source corpus does not provide additional technical detail beyond the vulnerability clas [truncated]

Known exploited Microsoft CVE published 2024-06-13

CVE-2024-26169

CVE-2024-26169 is a Microsoft Windows Error Reporting Service improper privilege management vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2024-06-13, with remediation due by 2024-07-04, and marked it as associated with known ransomware-campaign use. Organizations should treat it as a high-priority Windows remediation item.

HIGH Microsoft CVE published 2024-06-11

CVE-2024-30104

A remote code execution vulnerability in Microsoft Office allows an attacker to execute arbitrary code when a user opens a maliciously crafted file. The vulnerability requires user interaction and local attack vector access. Microsoft has released patches addressing this issue across multiple Office versions including Microsoft 365 Apps for Enterprise, Office 2016, Office 2019, and Office LTSC 2021 for bo [truncated]

HIGH Microsoft CVE published 2024-06-11

CVE-2024-30103

CVE-2024-30103 is a high-severity remote code execution vulnerability in Microsoft Outlook, published by NVD on June 11, 2024, with a CVSS 3.1 score of 8.8. The vulnerability affects multiple Microsoft Office and Outlook versions, including Microsoft 365 Apps for Enterprise (x64 and x86), Office 2019 (x64 and x86), Office LTSC 2021 (x64 and x86), and Outlook 2016 (x64 and x86). The attack vector is networ [truncated]

HIGH Microsoft CVE published 2024-06-11

CVE-2024-30101

CVE-2024-30101 is a remote code execution vulnerability in Microsoft Office, published by NVD on 2024-06-11 and last modified on 2026-05-19. The vulnerability carries a CVSS 3.1 score of 7.5 (HIGH) with the vector AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating network attack vector, high attack complexity, no privileges required, user interaction required, and high impacts to confidentiality, integrity, [truncated]

HIGH Microsoft CVE published 2024-06-11

CVE-2023-36792

CVE-2023-36792 is a Visual Studio Remote Code Execution vulnerability affecting Siemens ST7 ScadaConnect (6NH7997-5DA10-0AA0). Published on June 11, 2024, this vulnerability carries a HIGH severity CVSS score of 7.8. The vulnerability requires local attack vector access, low attack complexity, no privileges, but does require user interaction. Successful exploitation could result in high impact to confiden [truncated]