Fortra VM will include the Microsoft Patch Tuesday checks in the NIRV 4.44.0 and FVM Agent 2.8 releases.

  • Microsoft addressed 51 vulnerabilities in this release, including 1 rated as Critical and 18 Remote Code Execution vulnerabilities.
CVE/AdvisoryTitleTagMicrosoft Severity RatingBase ScoreMicrosoft ImpactExploitedPublicly Disclosed
CVE-2024-30069Windows Remote Access Connection Manager Information Disclosure VulnerabilityWindows Remote Access Connection ManagerImportant4.7Information DisclosureNoNo
CVE-2024-30070DHCP Server Service Denial of Service VulnerabilityWindows DHCP ServerImportant7.5Denial of ServiceNoNo
CVE-2024-30072Microsoft Event Trace Log File Parsing Remote Code Execution VulnerabilityWindows Event Logging ServiceImportant7.8Remote Code ExecutionNoNo
CVE-2024-30074Windows Link Layer Topology Discovery Protocol Remote Code Execution VulnerabilityWindows Link Layer Topology Discovery ProtocolImportant8Remote Code ExecutionNoNo
CVE-2024-30075Windows Link Layer Topology Discovery Protocol Remote Code Execution VulnerabilityWindows Link Layer Topology Discovery ProtocolImportant8Remote Code ExecutionNoNo
CVE-2024-30076Windows Container Manager Service Elevation of Privilege VulnerabilityWindows Container Manager ServiceImportant6.8Elevation of PrivilegeNoNo
CVE-2024-30077Windows OLE Remote Code Execution VulnerabilityMicrosoft WDAC OLE DB provider for SQLImportant8Remote Code ExecutionNoNo
CVE-2024-30078Windows Wi-Fi Driver Remote Code Execution VulnerabilityWindows Wi-Fi DriverImportant8.8Remote Code ExecutionNoNo
CVE-2024-30080Microsoft Message Queuing (MSMQ) Remote Code Execution VulnerabilityWindows Server ServiceCritical9.8Remote Code ExecutionNoNo
CVE-2024-30082Win32k Elevation of Privilege VulnerabilityWindows Win32K – GRFXImportant7.8Elevation of PrivilegeNoNo
CVE-2024-35250Windows Kernel-Mode Driver Elevation of Privilege VulnerabilityWindows Kernel-Mode DriversImportant7.8Elevation of PrivilegeNoNo
CVE-2024-35255Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege VulnerabilityAzure SDKImportant5.5Elevation of PrivilegeNoNo
CVE-2023-50868MITRE: CVE-2023-50868 NSEC3 closest encloser proof can exhaust CPUMicrosoft WindowsImportant7.5Denial of ServiceNoYes
CVE-2024-29187GitHub: CVE-2024-29187 WiX Burn-based bundles are vulnerable to binary hijack when run as SYSTEMVisual StudioImportant7.3Elevation of PrivilegeNoNo
CVE-2024-29060Visual Studio Elevation of Privilege VulnerabilityVisual StudioImportant6.7Elevation of PrivilegeNoNo
CVE-2024-30062Windows Standards-Based Storage Management Service Remote Code Execution VulnerabilityWindows Server ServiceImportant7.8Remote Code ExecutionNoNo
CVE-2024-30063Windows Distributed File System (DFS) Remote Code Execution VulnerabilityWindows Distributed File System (DFS)Important6.7Remote Code ExecutionNoNo
CVE-2024-30064Windows Kernel Elevation of Privilege VulnerabilityWindows KernelImportant8.8Elevation of PrivilegeNoNo
CVE-2024-30065Windows Themes Denial of Service VulnerabilityWindows ThemesImportant5.5Denial of ServiceNoNo
CVE-2024-30066Winlogon Elevation of Privilege VulnerabilityWinlogonImportant5.5Elevation of PrivilegeNoNo
CVE-2024-30067Winlogon Elevation of Privilege VulnerabilityWinlogonImportant5.5Elevation of PrivilegeNoNo
CVE-2024-30068Windows Kernel Elevation of Privilege VulnerabilityWindows KernelImportant8.8Elevation of PrivilegeNoNo
CVE-2024-30083Windows Standards-Based Storage Management Service Denial of Service VulnerabilityWindows Standards-Based Storage Management ServiceImportant7.5Denial of ServiceNoNo
CVE-2024-30084Windows Kernel-Mode Driver Elevation of Privilege VulnerabilityWindows Kernel-Mode DriversImportant7Elevation of PrivilegeNoNo
CVE-2024-30085Windows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityWindows Cloud Files Mini Filter DriverImportant7.8Elevation of PrivilegeNoNo
CVE-2024-30086Windows Win32 Kernel Subsystem Elevation of Privilege VulnerabilityWindows Win32 Kernel SubsystemImportant7.8Elevation of PrivilegeNoNo
CVE-2024-30087Win32k Elevation of Privilege VulnerabilityWindows Win32K – GRFXImportant7.8Elevation of PrivilegeNoNo
CVE-2024-30088Windows Kernel Elevation of Privilege VulnerabilityWindows NT OS KernelImportant7Elevation of PrivilegeNoNo
CVE-2024-30089Microsoft Streaming Service Elevation of Privilege VulnerabilityMicrosoft Streaming ServiceImportant7.8Elevation of PrivilegeNoNo
CVE-2024-30090Microsoft Streaming Service Elevation of Privilege VulnerabilityMicrosoft Streaming ServiceImportant7Elevation of PrivilegeNoNo
CVE-2024-30091Win32k Elevation of Privilege VulnerabilityWindows Win32K – GRFXImportant7.8Elevation of PrivilegeNoNo
CVE-2024-30093Windows Storage Elevation of Privilege VulnerabilityWindows StorageImportant7.3Elevation of PrivilegeNoNo
CVE-2024-30094Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityWindows Routing and Remote Access Service (RRAS)Important7.8Remote Code ExecutionNoNo
CVE-2024-30095Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityWindows Routing and Remote Access Service (RRAS)Important7.8Remote Code ExecutionNoNo
CVE-2024-30096Windows Cryptographic Services Information Disclosure VulnerabilityWindows Cryptographic ServicesImportant5.5Information DisclosureNoNo
CVE-2024-30097Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution VulnerabilityMicrosoft Windows SpeechImportant8.8Remote Code ExecutionNoNo
CVE-2024-30099Windows Kernel Elevation of Privilege VulnerabilityWindows NT OS KernelImportant7Elevation of PrivilegeNoNo
CVE-2024-30100Microsoft SharePoint Server Remote Code Execution VulnerabilityMicrosoft Office SharePointImportant7.8Remote Code ExecutionNoNo
CVE-2024-30101Microsoft Office Remote Code Execution VulnerabilityMicrosoft OfficeImportant7.5Remote Code ExecutionNoNo
CVE-2024-30102Microsoft Office Remote Code Execution VulnerabilityMicrosoft Office WordImportant7.3Remote Code ExecutionNoNo
CVE-2024-30103Microsoft Outlook Remote Code Execution VulnerabilityMicrosoft Office OutlookImportant8.8Remote Code ExecutionNoNo
CVE-2024-30104Microsoft Office Remote Code Execution VulnerabilityMicrosoft OfficeImportant7.8Remote Code ExecutionNoNo
CVE-2024-35248Microsoft Dynamics 365 Business Central Elevation of Privilege VulnerabilityDynamics Business CentralImportant7.3Elevation of PrivilegeNoNo
CVE-2024-35249Microsoft Dynamics 365 Business Central Remote Code Execution VulnerabilityDynamics Business CentralImportant8.8Remote Code ExecutionNoNo
CVE-2024-35252Azure Storage Movement Client Library Denial of Service VulnerabilityAzure Storage LibraryImportant7.5Denial of ServiceNoNo
CVE-2024-35253Microsoft Azure File Sync Elevation of Privilege VulnerabilityAzure File SyncImportant4.4Elevation of PrivilegeNoNo
CVE-2024-35254Azure Monitor Agent Elevation of Privilege VulnerabilityAzure MonitorImportant7.1Elevation of PrivilegeNoNo
CVE-2024-35263Microsoft Dynamics 365 (On-Premises) Information Disclosure VulnerabilityMicrosoft DynamicsImportant5.7Information DisclosureNoNo
CVE-2024-35265Windows Perception Service Elevation of Privilege VulnerabilityWindows Perception ServiceImportant7Elevation of PrivilegeNoNo
CVE-2024-37325Azure Science Virtual Machine (DSVM) Elevation of Privilege VulnerabilityAzure Data Science Virtual MachinesImportant8.1Elevation of PrivilegeNoNo
CVE-2024-30052Visual Studio Remote Code Execution VulnerabilityVisual StudioImportant4.7Remote Code ExecutionNoNo

Quickly Find and Fix Your Most At-Risk Weaknesses

Watch this demo to see how Frontline VM can help.