Microsoft April 2024 Security Updates


  1. Posts : 196
    10
       #1

    Microsoft April 2024 Security Updates


    This release consists of the following 149 Microsoft CVEs:
    Tag CVE Base Score CVSS Vector Exploitability FAQs? Workarounds? Mitigations?
    Windows BitLocker CVE-2024-20665
    Windows Secure Boot CVE-2024-20669
    Microsoft Office Outlook CVE-2024-20670
    Azure Private 5G Core CVE-2024-20685
    Windows Secure Boot CVE-2024-20688
    Windows Secure Boot CVE-2024-20689
    Windows Kernel CVE-2024-20693
    Microsoft Defender for IoT CVE-2024-21322
    Microsoft Defender for IoT CVE-2024-21323
    Microsoft Defender for IoT CVE-2024-21324
    .NET and Visual Studio CVE-2024-21409
    Azure Compute Gallery CVE-2024-21424
    Windows Authentication Methods CVE-2024-21447
    Microsoft Install Service CVE-2024-26158
    Windows Secure Boot CVE-2024-26168
    Windows Secure Boot CVE-2024-26171
    Windows DWM Core Library CVE-2024-26172
    Windows Secure Boot CVE-2024-26175
    Windows Routing and Remote Access Service (RRAS) CVE-2024-26179
    Windows Secure Boot CVE-2024-26180
    Windows Kerberos CVE-2024-26183
    Windows Secure Boot CVE-2024-26189
    Azure Migrate CVE-2024-26193
    Windows Secure Boot CVE-2024-26194
    Windows DHCP Server CVE-2024-26195
    Windows Routing and Remote Access Service (RRAS) CVE-2024-26200
    Windows DHCP Server CVE-2024-26202
    Windows Routing and Remote Access Service (RRAS) CVE-2024-26205
    Windows Remote Access Connection Manager CVE-2024-26207
    Windows Message Queuing CVE-2024-26208
    Windows Local Security Authority Subsystem Service (LSASS) CVE-2024-26209
    Microsoft WDAC OLE DB provider for SQL CVE-2024-26210
    Windows Remote Access Connection Manager CVE-2024-26211
    Windows DHCP Server CVE-2024-26212
    Microsoft Brokering File System CVE-2024-26213
    Microsoft WDAC ODBC Driver CVE-2024-26214
    Windows DHCP Server CVE-2024-26215
    Windows File Server Resource Management Service CVE-2024-26216
    Windows Remote Access Connection Manager CVE-2024-26217
    Windows Kernel CVE-2024-26218
    Windows HTTP.sys CVE-2024-26219
    Windows Mobile Hotspot CVE-2024-26220
    Role: DNS Server CVE-2024-26221
    Role: DNS Server CVE-2024-26222
    Role: DNS Server CVE-2024-26223
    Role: DNS Server CVE-2024-26224
    Windows Distributed File System (DFS) CVE-2024-26226
    Role: DNS Server CVE-2024-26227
    Windows Cryptographic Services CVE-2024-26228
    Windows Kernel CVE-2024-26229
    Windows Remote Access Connection Manager CVE-2024-26230
    Role: DNS Server CVE-2024-26231
    Windows Message Queuing CVE-2024-26232
    Role: DNS Server CVE-2024-26233
    Windows Proxy Driver CVE-2024-26234
    Windows Update Stack CVE-2024-26235
    Windows Update Stack CVE-2024-26236
    Windows Defender Credential Guard CVE-2024-26237
    Windows Remote Access Connection Manager CVE-2024-26239
    Windows Secure Boot CVE-2024-26240
    Windows Win32K - ICOMP CVE-2024-26241
    Windows Telephony Server CVE-2024-26242
    Windows USB Print Driver CVE-2024-26243
    Microsoft WDAC OLE DB provider for SQL CVE-2024-26244
    Windows Kernel CVE-2024-26245
    Windows Kerberos CVE-2024-26248
    Windows Secure Boot CVE-2024-26250
    Microsoft Office SharePoint CVE-2024-26251
    Windows Internet Connection Sharing (ICS) CVE-2024-26252
    Windows Internet Connection Sharing (ICS) CVE-2024-26253
    Windows Virtual Machine Bus CVE-2024-26254
    Windows Remote Access Connection Manager CVE-2024-26255
    Windows Compressed Folder CVE-2024-26256
    Microsoft Office Excel CVE-2024-26257
    Windows Secure Boot CVE-2024-28896
    Windows Secure Boot CVE-2024-28897
    Windows Secure Boot CVE-2024-28898
    Windows Remote Access Connection Manager CVE-2024-28900
    Windows Remote Access Connection Manager CVE-2024-28901
    Windows Remote Access Connection Manager CVE-2024-28902
    Windows Secure Boot CVE-2024-28903
    Microsoft Brokering File System CVE-2024-28904
    Microsoft Brokering File System CVE-2024-28905
    SQL Server CVE-2024-28906
    Microsoft Brokering File System CVE-2024-28907
    SQL Server CVE-2024-28908
    SQL Server CVE-2024-28909
    SQL Server CVE-2024-28910
    SQL Server CVE-2024-28911
    SQL Server CVE-2024-28912
    SQL Server CVE-2024-28913
    SQL Server CVE-2024-28914
    SQL Server CVE-2024-28915
    Azure Arc CVE-2024-28917
    Windows Secure Boot CVE-2024-28919
    Windows Secure Boot CVE-2024-28920
    Windows Secure Boot CVE-2024-28921
    Windows Secure Boot CVE-2024-28922
    Windows Secure Boot CVE-2024-28923
    Windows Secure Boot CVE-2024-28924
    Windows Secure Boot CVE-2024-28925
    SQL Server CVE-2024-28926
    SQL Server CVE-2024-28927
    SQL Server CVE-2024-28929
    SQL Server CVE-2024-28930
    SQL Server CVE-2024-28931
    SQL Server CVE-2024-28932
    SQL Server CVE-2024-28933
    SQL Server CVE-2024-28934
    SQL Server CVE-2024-28935
    SQL Server CVE-2024-28936
    SQL Server CVE-2024-28937
    SQL Server CVE-2024-28938
    SQL Server CVE-2024-28939
    SQL Server CVE-2024-28940
    SQL Server CVE-2024-28941
    SQL Server CVE-2024-28942
    SQL Server CVE-2024-28943
    SQL Server CVE-2024-28944
    SQL Server CVE-2024-28945
    SQL Server CVE-2024-29043
    SQL Server CVE-2024-29044
    SQL Server CVE-2024-29045
    SQL Server CVE-2024-29046
    SQL Server CVE-2024-29047
    SQL Server CVE-2024-29048
    Microsoft Edge (Chromium-based) CVE-2024-29049
    Windows Cryptographic Services CVE-2024-29050
    Windows Storage CVE-2024-29052
    Microsoft Defender for IoT CVE-2024-29053
    Microsoft Defender for IoT CVE-2024-29054
    Microsoft Defender for IoT CVE-2024-29055
    Windows Authentication Methods CVE-2024-29056
    Windows Secure Boot CVE-2024-29061
    Windows Secure Boot CVE-2024-29062
    Azure AI Search CVE-2024-29063
    Role: Windows Hyper-V CVE-2024-29064
    Windows Distributed File System (DFS) CVE-2024-29066
    Microsoft Edge (Chromium-based) CVE-2024-29981
    SQL Server CVE-2024-29982
    SQL Server CVE-2024-29983
    SQL Server CVE-2024-29984
    SQL Server CVE-2024-29985
    Internet Shortcut Files CVE-2024-29988
    Azure Monitor CVE-2024-29989
    Microsoft Azure Kubernetes Service CVE-2024-29990
    Azure SDK CVE-2024-29992
    Azure CVE-2024-29993


    We are republising 6 non-Microsoft CVEs:
    CNA Tag CVE FAQs? Workarounds? Mitigations?
    Intel Corporation Intel CVE-2024-2201
    Lenovo Windows Secure Boot CVE-2024-23593
    Lenovo Windows Secure Boot CVE-2024-23594
    Chrome Microsoft Edge (Chromium-based) CVE-2024-3156
    Chrome Microsoft Edge (Chromium-based) CVE-2024-3158
    Chrome Microsoft Edge (Chromium-based) CVE-2024-3159


    Security Update Guide Blog Posts
    Date Blog Post
    April 9, 2024 Toward greater transparency: Security Update Guide now shares CWEs for CVEs
    January 11, 2022 Coming Soon: New Security Update Guide Notification System
    February 9, 2021 Continuing to Listen: Good News about the Security Update Guide API
    January 13, 2021 Security Update Guide Supports CVEs Assigned by Industry Partners
    December 8, 2020 Security Update Guide: Let’s keep the conversation going
    November 9, 2020 Vulnerability Descriptions in the New Version of the Security Update Guide


    Relevant Resources

    • The new Hotpatching feature is now generally available. Please see Hotpatching feature for Windows Server Azure Edition virtual machines (VMs) for more information.
    • Windows 10 and Windows 11 updates are cumulative. The monthly security release includes all security fixes for vulnerabilities that affect Windows 10 and Windows 11, in addition to non-security updates. The updates are available via the Microsoft Update Catalog. For information on lifecycle and support dates for Windows 10 and Windows 11 operating systems, please see Windows Lifecycle Facts Sheet.
    • Microsoft is improving Windows Release Notes. For more information, please see What's next for Windows release notes.
    • A list of the latest servicing stack updates for each operating system can be found in ADV990001. This list will be updated whenever a new servicing stack update is released. It is important to install the latest servicing stack update.
    • In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features.
    • Customers running Windows Server 2008 R2, or Windows Server 2008 need to purchase the Extended Security Update to continue receiving security updates. See 4522133 for more information.

    Known Issues
    You can see these in more detail from the Deployments tab by selecting Known Issues column in the Edit Columns panel.


    For more information about Windows Known Issues, please see Windows message center (links to currently-supported versions of Windows are in the left pane).


    KB Article Applies To
    5036892 Windows 10, version 21H2, Windows 10, version 22H2
    5036932 Windows Server 2008 (Monthly Rollup)
    5036950 Windows Server 2008 (Security-only update)
    Released: Apr 9, 2024


    April 2024 Security Updates - Release Notes - Security Update Guide - Microsoft
    Last edited by NICK ADSL UK; 4 Weeks Ago at 05:46.
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 09:32.
Find Us




Windows 10 Forums