CVE-2024-43624 Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerability

Posted on Tuesday November 12, 2024

Information published.

 

CVE-2024-43511 Windows Kernel Elevation of Privilege Vulnerability

Posted on Tuesday November 12, 2024

The following updates have been made: 1) To comprehensively address this vulnerability, Microsoft has released October 2024 security updates for all affected client versions of Windows 10 and Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022. Microsoft recommends that customers install the updates to be fully protected from the vulnerability. Customers whose systems are configured to receive automatic updates do not need to take any further action.2) FAQ added to explain further recommended actions to take after installing the November 2024 security update: This update affects a component of Virtualization-based Security (VBS). The policy mitigations described in [KB5042562: Guidance for blocking rollback of Virtualization-based Security (VBS) related security updates - Microsoft Support](https://support.microsoft.com/en-us/topic/kb5042562-guidance-for-blocking-rollback-of-virtualization-based-security-vbs-related-security-updates-b2e7ebf4-f64d-4884-a390-38d63171b8d3) have been updated to accommodate these changes. If you have previously applied the mitigation policies, we recommend that you consider updating to the latest policies.

 

CVE-2024-43516 Windows Secure Kernel Mode Elevation of Privilege Vulnerability

Posted on Tuesday November 12, 2024

The following updates have been made: 1) To comprehensively address this vulnerability, Microsoft has released October 2024 security updates for all affected client versions of Windows 10 and Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022. Microsoft recommends that customers install the updates to be fully protected from the vulnerability. Customers whose systems are configured to receive automatic updates do not need to take any further action.2) FAQ added to explain further recommended actions to take after installing the November 2024 security update: This update affects a component of Virtualization-based Security (VBS). The policy mitigations described in [KB5042562: Guidance for blocking rollback of Virtualization-based Security (VBS) related security updates - Microsoft Support](https://support.microsoft.com/en-us/topic/kb5042562-guidance-for-blocking-rollback-of-virtualization-based-security-vbs-related-security-updates-b2e7ebf4-f64d-4884-a390-38d63171b8d3) have been updated to accommodate these changes. If you have previously applied the mitigation policies, we recommend that you consider updating to the latest policies.

 

CVE-2024-43528 Windows Secure Kernel Mode Elevation of Privilege Vulnerability

Posted on Tuesday November 12, 2024

The following updates have been made: 1) To comprehensively address this vulnerability, Microsoft has released October 2024 security updates for all affected client versions of Windows 10 and Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022. Microsoft recommends that customers install the updates to be fully protected from the vulnerability. Customers whose systems are configured to receive automatic updates do not need to take any further action.2) FAQ added to explain further recommended actions to take after installing the November 2024 security update: This update affects a component of Virtualization-based Security (VBS). The policy mitigations described in [KB5042562: Guidance for blocking rollback of Virtualization-based Security (VBS) related security updates - Microsoft Support](https://support.microsoft.com/en-us/topic/kb5042562-guidance-for-blocking-rollback-of-virtualization-based-security-vbs-related-security-updates-b2e7ebf4-f64d-4884-a390-38d63171b8d3) have been updated to accommodate these changes. If you have previously applied the mitigation policies, we recommend that you consider updating to the latest policies.

 

CVE-2024-43601 Visual Studio Code for Linux Remote Code Execution Vulnerability

Posted on Friday November 08, 2024

Updated the CVSS score and corrected FAQs. This is an informational change only.

 

Chromium: CVE-2024-10827 Use after free in Serial

Posted on Thursday November 07, 2024

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024) for more information.

 

Page:   1...137138139140141142143144145...172

Celebrating 35+ Years

Off-Site Cloud Backups

Contact Us

Support Ends for Windows 10 22H2, Windows Server 2012 R2, Exchange 2013, Office 2016