Threat intelligence

Microsoft Security Bulletin Coverage for November 2024

by Security News

Overview

Microsoft’s November 2024 Patch Tuesday has 89 vulnerabilities, of which 51 are Remote Code Execution. SonicWall Capture Labs threat research team has analyzed and addressed Microsoft’s security advisories for the month of November2024 and has produced coverage for 6 of the reported vulnerabilities

Vulnerabilities with Detections

CVECVE TitleSignature
CVE-2024-43451NTLM Hash Disclosure Spoofing VulnerabilityASPY 7021 Malformed-url url.MP_1
CVE-2024-43623Windows NT OS Kernel Elevation of Privilege VulnerabilityASPY 7018 Exploit-exe exe.MP_417
CVE-2024-43629Windows DWM Core Library Elevation of Privilege VulnerabilityASPY 7019 Exploit-exe exe.MP_418
CVE-2024-43630Windows Kernel Elevation of Privilege VulnerabilityASPY 7020 Exploit-exe exe.MP_419
CVE-2024-49019Active Directory Certificate Services Elevation of Privilege VulnerabilityIPS 4339 Microsoft Active Directory Certificate Services EoP (CVE-2024-49019)
CVE-2024-49033Microsoft Word Security Feature Bypass VulnerabilityIPS 4338 Microsoft Word Security Feature Bypass (CVE-2024-49033)

Release Breakdown

The vulnerabilities can be classified into following categories:

For November there are 4 critical, 84 Important and 1 moderate vulnerability.

Microsoft tracks vulnerabilities that are being actively exploited at the time of discovery and those that have been disclosed publicly before the patch Tuesday release for each month. The above chart displays these metrics as seen each month.

Release Detailed Breakdown

Defense in Depth Vulnerabilities
CVECVE Title
CVE-2024-49049Visual Studio Code Remote Extension Elevation of Privilege Vulnerability
Denial of Service Vulnerabilities
CVECVE Title
CVE-2024-38264Microsoft Virtual Hard Disk (VHDX) Denial of Service Vulnerability
CVE-2024-43499.NET and Visual Studio Denial of Service Vulnerability
CVE-2024-43633Windows Hyper-V Denial of Service Vulnerability
CVE-2024-43642Windows SMB Denial of Service Vulnerability
Elevation of Privilege Vulnerabilities
CVECVE Title
CVE-2024-43449Windows USB Video Class System Driver Elevation of Privilege Vulnerability
CVE-2024-43452Windows Registry Elevation of Privilege Vulnerability
CVE-2024-43530Windows Update Stack Elevation of Privilege Vulnerability
CVE-2024-43613Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability
CVE-2024-43623Windows NT OS Kernel Elevation of Privilege Vulnerability
CVE-2024-43624Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerability
CVE-2024-43625Microsoft Windows VMSwitch Elevation of Privilege Vulnerability
CVE-2024-43626Windows Telephony Service Elevation of Privilege Vulnerability
CVE-2024-43629Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2024-43630Windows Kernel Elevation of Privilege Vulnerability
CVE-2024-43631Windows Secure Kernel Mode Elevation of Privilege Vulnerability
CVE-2024-43634Windows USB Video Class System Driver Elevation of Privilege Vulnerability
CVE-2024-43636Win32k Elevation of Privilege Vulnerability
CVE-2024-43637Windows USB Video Class System Driver Elevation of Privilege Vulnerability
CVE-2024-43638Windows USB Video Class System Driver Elevation of Privilege Vulnerability
CVE-2024-43640Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
CVE-2024-43641Windows Registry Elevation of Privilege Vulnerability
CVE-2024-43643Windows USB Video Class System Driver Elevation of Privilege Vulnerability
CVE-2024-43644Windows Client-Side Caching Elevation of Privilege Vulnerability
CVE-2024-43646Windows Secure Kernel Mode Elevation of Privilege Vulnerability
CVE-2024-49019Active Directory Certificate Services Elevation of Privilege Vulnerability
CVE-2024-49039Windows Task Scheduler Elevation of Privilege Vulnerability
CVE-2024-49042Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability
CVE-2024-49044Visual Studio Elevation of Privilege Vulnerability
CVE-2024-49046Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
CVE-2024-49051Microsoft PC Manager Elevation of Privilege Vulnerability
CVE-2024-49056Airlift.microsoft.com Elevation of Privilege Vulnerability
Information Disclosure Vulnerabilities
CVECVE Title
CVE-2024-38203Windows Package Library Manager Information Disclosure Vulnerability
Remote Code Execution Vulnerabilities
CVECVE Title
CVE-2024-38255SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-43447Windows SMBv3 Server Remote Code Execution Vulnerability
CVE-2024-43459SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-43462SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-43498.NET and Visual Studio Remote Code Execution Vulnerability
CVE-2024-43598LightGBM Remote Code Execution Vulnerability
CVE-2024-43602Azure CycleCloud Remote Code Execution Vulnerability
CVE-2024-43620Windows Telephony Service Remote Code Execution Vulnerability
CVE-2024-43621Windows Telephony Service Remote Code Execution Vulnerability
CVE-2024-43622Windows Telephony Service Remote Code Execution Vulnerability
CVE-2024-43627Windows Telephony Service Remote Code Execution Vulnerability
CVE-2024-43628Windows Telephony Service Remote Code Execution Vulnerability
CVE-2024-43635Windows Telephony Service Remote Code Execution Vulnerability
CVE-2024-43639Windows Kerberos Remote Code Execution Vulnerability
CVE-2024-48993SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-48994SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-48995SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-48996SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-48997SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-48998SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-48999SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49000SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49001SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49002SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49003SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49004SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49005SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49006SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49007SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49008SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49009SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49010SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49011SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49012SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49013SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49014SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49015SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49016SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49017SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49018SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49021Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2024-49026Microsoft Excel Remote Code Execution Vulnerability
CVE-2024-49027Microsoft Excel Remote Code Execution Vulnerability
CVE-2024-49028Microsoft Excel Remote Code Execution Vulnerability
CVE-2024-49029Microsoft Excel Remote Code Execution Vulnerability
CVE-2024-49030Microsoft Excel Remote Code Execution Vulnerability
CVE-2024-49031Microsoft Office Graphics Remote Code Execution Vulnerability
CVE-2024-49032Microsoft Office Graphics Remote Code Execution Vulnerability
CVE-2024-49043Microsoft.SqlServer.XEvent.Configuration.dll Remote Code Execution Vulnerability
CVE-2024-49048TorchGeo Remote Code Execution Vulnerability
CVE-2024-49050Visual Studio Code Python Extension Remote Code Execution Vulnerability
Security Feature Bypass Vulnerabilities
CVECVE Title
CVE-2024-43645Windows Defender Application Control (WDAC) Security Feature Bypass Vulnerability
CVE-2024-49033Microsoft Word Security Feature Bypass Vulnerability
Spoofing Vulnerabilities
CVECVE Title
CVE-2024-43450Windows DNS Spoofing Vulnerability
CVE-2024-43451NTLM Hash Disclosure Spoofing Vulnerability
CVE-2024-49040Microsoft Exchange Server Spoofing Vulnerability

Share This Article

An Article By

Security News

The SonicWall Capture Labs Threat Research Team gathers, analyzes and vets cross-vector threat information from the SonicWall Capture Threat network, consisting of global devices and resources, including more than 1 million security sensors in nearly 200 countries and territories. The research team identifies, analyzes, and mitigates critical vulnerabilities and malware daily through in-depth research, which drives protection for all SonicWall customers. In addition to safeguarding networks globally, the research team supports the larger threat intelligence community by releasing weekly deep technical analyses of the most critical threats to small businesses, providing critical knowledge that defenders need to protect their networks.

Related Articles

  • File shredder malware spitefully deletes files and celebrates
    Read More
  • Debug build of Jigsaw Ransomware contains SMTP email credentials
    Read More
  • Apache Struts Unauthorized Arbitrary File Upload
    Read More