Microsoft February 2024 Security Updates

Anonymous
2024-02-13T18:16:34+00:00

February 2024 Security Updates **This release consists of the following 73 Microsoft CVEs:**Tag CVE Base Score CVSS Vector Exploitability FAQs? Workarounds? **Mitigations?**Azure DevOps CVE-2024-20667Microsoft Office CVE-2024-20673Azure Stack CVE-2024-20679Windows Hyper-V CVE-2024-20684Skype for Business CVE-2024-20695Trusted Compute Base CVE-2024-21304Microsoft Defender for Endpoint CVE-2024-21315Microsoft Dynamics CVE-2024-21327Microsoft Dynamics CVE-2024-21328Azure Connected Machine Agent CVE-2024-21329Windows Kernel CVE-2024-21338Windows USB Serial Driver CVE-2024-21339Windows Kernel CVE-2024-21340Windows Kernel CVE-2024-21341Role: DNS Server CVE-2024-21342Windows Internet Connection Sharing (ICS) CVE-2024-21343Windows Internet Connection Sharing (ICS) CVE-2024-21344Windows Kernel CVE-2024-21345Windows Win32K - ICOMP CVE-2024-21346SQL Server CVE-2024-21347Windows Internet Connection Sharing (ICS) CVE-2024-21348Microsoft ActiveX CVE-2024-21349Microsoft WDAC OLE DB provider for SQL CVE-2024-21350Windows SmartScreen CVE-2024-21351Microsoft WDAC OLE DB provider for SQL CVE-2024-21352Microsoft WDAC ODBC Driver CVE-2024-21353Windows Message Queuing CVE-2024-21354Windows Message Queuing CVE-2024-21355Windows LDAP - Lightweight Directory Access Protocol CVE-2024-21356Windows Internet Connection Sharing (ICS) CVE-2024-21357Microsoft WDAC OLE DB provider for SQL CVE-2024-21358Microsoft WDAC OLE DB provider for SQL CVE-2024-21359Microsoft WDAC OLE DB provider for SQL CVE-2024-21360Microsoft WDAC OLE DB provider for SQL CVE-2024-21361Windows Kernel CVE-2024-21362Windows Message Queuing CVE-2024-21363Azure Site Recovery CVE-2024-21364Microsoft WDAC OLE DB provider for SQL CVE-2024-21365Microsoft WDAC OLE DB provider for SQL CVE-2024-21366Microsoft WDAC OLE DB provider for SQL CVE-2024-21367Microsoft WDAC OLE DB provider for SQL CVE-2024-21368Microsoft WDAC OLE DB provider for SQL CVE-2024-21369Microsoft WDAC OLE DB provider for SQL CVE-2024-21370Windows Kernel CVE-2024-21371Windows OLE CVE-2024-21372Microsoft Teams for Android CVE-2024-21374Microsoft WDAC OLE DB provider for SQL CVE-2024-21375Microsoft Azure Kubernetes Service CVE-2024-21376Microsoft Windows DNS CVE-2024-21377Microsoft Office Outlook CVE-2024-21378Microsoft Office Word CVE-2024-21379Microsoft Dynamics CVE-2024-21380Azure Active Directory CVE-2024-21381Microsoft Office OneNote CVE-2024-21384.NET CVE-2024-21386Microsoft Dynamics CVE-2024-21389Microsoft WDAC OLE DB provider for SQL CVE-2024-21391Microsoft Dynamics CVE-2024-21393Microsoft Dynamics CVE-2024-21394Microsoft Dynamics CVE-2024-21395Microsoft Dynamics CVE-2024-21396Azure File Sync CVE-2024-21397Microsoft Edge (Chromium-based) CVE-2024-21399Azure Active Directory CVE-2024-21401Microsoft Office Outlook CVE-2024-21402Microsoft Azure Kubernetes Service CVE-2024-21403.NET CVE-2024-21404Windows Message Queuing CVE-2024-21405Microsoft Windows CVE-2024-21406Microsoft Exchange Server CVE-2024-21410Internet Shortcut Files CVE-2024-21412Microsoft Office CVE-2024-21413Microsoft WDAC OLE DB provider for SQL CVE-2024-21420**We are republising 6 non-Microsoft CVEs:**CNA Tag CVE FAQs? Workarounds? Mitigations?MITRE Role: DNS Server CVE-2023-50387 No No NoChrome Microsoft Edge (Chromium-based) CVE-2024-1059 Yes No NoChrome Microsoft Edge (Chromium-based) CVE-2024-1060 Yes No NoChrome Microsoft Edge (Chromium-based) CVE-2024-1077 Yes No NoChrome Microsoft Edge (Chromium-based) CVE-2024-1283 Yes No NoChrome Microsoft Edge (Chromium-based) CVE-2024-1284 Yes No NoSecurity Update Guide Blog Posts****Date Blog PostJanuary 11, 2022 Coming Soon: New Security Update Guide Notification SystemFebruary 9, 2021 Continuing to Listen: Good News about the Security Update Guide APIJanuary 13, 2021 Security Update Guide Supports CVEs Assigned by Industry PartnersDecember 8, 2020 Security Update Guide: Let’s keep the conversation goingNovember 9, 2020 Vulnerability Descriptions in the New Version of the Security Update GuideRelevant Resources

  • The new Hotpatching feature is now generally available. Please see Hotpatching feature for Windows Server Azure Edition virtual machines (VMs) for more information.
  • Windows 10 updates are cumulative. The monthly security release includes all security fixes for vulnerabilities that affect Windows 10, in addition to non-security updates. The updates are available via the Microsoft Update Catalog. For information on lifecycle and support dates for Windows 10 operating systems, please see Windows Lifecycle Facts Sheet.
  • Microsoft is improving Windows Release Notes. For more information, please see What's next for Windows release notes.
  • A list of the latest servicing stack updates for each operating system can be found in ADV990001. This list will be updated whenever a new servicing stack update is released. It is important to install the latest servicing stack update.
  • In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features.
  • Customers running Windows 7, Windows Server 2008 R2, or Windows Server 2008 need to purchase the Extended Security Update to continue receiving security updates. See 4522133 for more information.

Known IssuesYou can see these in more detail from the Deployments tab by selecting Known Issues column in the Edit Columns panel.For more information about Windows Known Issues, please see Windows message center (links to currently-supported versions of Windows are in the left pane).KB Article Applies To5034763 Windows 10, version 21H2, Windows 10, version 22H25034770 Windows Server 20225034795 Windows Server 2008 (Monthly Rollup)5034833 Windows Server 2008 R2 (Security-only update)5035606 Exchange Server 2019Released: Feb 13, 2024February 2024 Security Updates - Release Notes - Security Update Guide - Microsoft

Windows for home | Windows 11 | Windows update

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Anonymous
    2024-02-20T16:04:01+00:00

    Dear NICK ADSL UK

    Thank you for posting in the Microsoft community.

    Thank you for organizing and sharing your enthusiasm.

    This is very valuable to all information security personnel.

    I will personally bookmark it as well

    Thanks again for your enthusiasm.

    Best Wish

    Shawn Z | Microsoft Community Support Specialist

    0 comments No comments