Misaligned KBs for CVE-2024-21413 creating bugs

Valentina De Feo 0 Reputation points
2025-06-03T09:34:05.4966667+00:00

Good morning,

maybe someone can give me a heads up.

One of the customers in my company has reported a bug, claiming that over 300 machines are vulnerable to CVE-2024-21413.

They say they have installed KB5002700, that based on the info in the Microsoft catalog is a replacement/update to KB5002537 (which initially was the one fixing CVE-2024-21413).

https://catalog.update.microsoft.com/ScopedViewInline.aspx?updateid=db98fa3f-5d82-4072-bd2f-28bbfd2b9107#PackageDetails

User's image

The issue is that the customer still sees the vulnerability being present even with the updated KB. And they are not able to install the older KB (5002537) as it won’t install because it says its already there (yet that particular KB is NOT installed, but a superseded update has been -> KB5002700) 

After some research it looks like MSRC is not reporting KB5002700 as one of the fixes for CVE-2024-21413

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21413

image.png

So it seems there is a misalignment between the MS Catalog and MSRC.

Can someone help me understand if Im missing something or if this is an actual mistake?

Thank you

Microsoft 365 and Office | Development | Microsoft 365 Developer Program
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.